VPN, Proxy and Data Center IP Detection: How It Works and When to Block

VPN, proxy and data center IP detection is the foundation of network-level traffic filtering. Here is what lies behind the words ASN, hosting IP and residential proxy, and how to use these signals without losing real visitors.

Bots and Fraud9 min read
VPN, Proxy and Data Center IP Detection: How It Works and When to Block
Contents
  1. How an IP address works: networks, ISPs, ASN
  2. Data center IP detection: how hosting IPs are identified
  3. VPN detection
  4. Proxy detection
  5. IPv6 and visits without an ISP
  6. Where network filtering gets it wrong
  7. How this is set up in ArtisanClo
  8. Example: three visits, broken down
  9. Practical recommendations
  10. In short

Network signals are the first thing any traffic filter sees and the cheapest to check: before the page even loads, you know which address the visit came from and who owns it. That is why VPN, proxy and data center IP detection sits at the base of almost every bot protection setup. It is also where real people are easiest to block by mistake if you do not understand how these signals work.

How an IP address works: networks, ISPs, ASN

The internet is made up of many networks, each run by a single organization. Such a network is called an autonomous system, and its number is the ASN (for example, AS15169). Every public IP address belongs to some autonomous system.

Based on the ASN and network owner data, addresses fall into several types:

Network type Owner Who usually comes from it
Residential ISP internet service provider ordinary users on Wi-Fi
Mobile carrier cellular company smartphone users
Hosting, cloud, data center hosting companies and cloud platforms servers, scripts, VPNs, proxies, scanners
Corporate network company or institution employees behind a shared exit
Educational network university students, staff

For advertising, the key distinction is simple: a real person goes online through an ISP or a carrier, while a program runs on a server. A visit from a cloud hosting network on an ad link almost always means automation.

Where IP data comes from

Which network an address belongs to is public: it is visible in internet address registries and routing tables. On top of that, specialized databases collect extra details: network type, ISP, geolocation, and signs of VPNs, proxies and anonymization nodes. No database is perfect, since addresses get resold and networks change purpose, so good filters use them as one signal among many, not as a final verdict.

Data center IP detection: how hosting IPs are identified

A hosting IP is an address that belongs to a cloud platform, VPS provider or data center. It is identified:

  1. By ASN. The networks of major clouds and hosting providers are known and stable.
  2. By range owner. The range's registration data names a hosting or cloud company.
  3. By the lack of a subscriber ISP. A server address often has no recognizable consumer ISP, which is a sign in itself.
  4. By observation. If bots keep coming from a network's addresses, the network earns a bad reputation. More in IP reputation.

Blocking data center ASNs is one of the most effective measures against scanners, scrapers and spy tools, covered in detail in protection from spy tools. It rarely hits real people, but it does: cloud browsers and some corporate exits also run on servers.

VPN detection

A VPN encrypts traffic and sends it out to the internet through the VPN provider's server. To the site, the visit looks as if it came from that server. Signs of a VPN:

  • The address is in a database of known VPN nodes. Large commercial VPNs use thousands of addresses, and they become known quickly.
  • A hosting network. Most VPN servers sit in data centers.
  • Inconsistency with the browser. The system time zone says Moscow while the IP is in the Netherlands; the browser language is Vietnamese while the geo is Germany.
  • Real address leaks. Sometimes the browser exposes the real address through separate connection channels, and it does not match the request address.

Who uses a VPN

Scrapers, spy tools and ordinary people all come through VPNs. The share of ordinary people depends heavily on the country: in some places a VPN is exotic, in others it is everyday. So a blanket VPN block is a decision for a specific geo and offer, not a default setting. It is safer to lower trust in the visit and weigh the VPN together with other signals.

Proxy detection

A proxy is an intermediary the request goes through. There are several kinds, and each is detected differently.

Server proxies

They run in data centers, so they give themselves away just like hosting IPs. Some proxies also add service headers to the request that reveal them immediately.

Residential proxies

Traffic exits through the address of an ordinary home user, most often via an app the user installed without reading the terms. At the network level such a visit is indistinguishable from a subscriber. Residential proxies are detected indirectly:

  • the address shows up in databases as seen proxying;
  • the browser's behavior does not match what is expected from that network and geo;
  • visits with different browser fingerprints come from the address within a short time.

Mobile proxies

They work through mobile carrier SIM cards. They are especially hard to cut off: hundreds of real subscribers already share one mobile address, and blocking the whole address means cutting live traffic.

Tip. Network checks are nearly powerless against residential and mobile proxies. What works there are browser and behavior checks, covered in headless browsers and browser fingerprinting.

IPv6 and visits without an ISP

Two related signals that are often turned on by mistake.

  • IPv6. Many mobile carriers give subscribers IPv6 addresses, so blocking IPv6 can cut a big chunk of mobile traffic. It is justified only if both your offer and your tracker work over IPv4.
  • No ISP. If an address has no identifiable ISP, it is usually a server. For most platforms the signal is useful, but for part of TikTok traffic, for example, it causes false positives.

Where network filtering gets it wrong

Situation What the filter sees What it really is
Office employee corporate network, many visits from one address a real person
Cloud browser or data saver the company's server address a real person
Traveler roaming, a «foreign» geo, mismatched time zone a real person
Residential proxy residential ISP a bot or spy tool
Mobile proxy mobile carrier a bot or account farm

The takeaway: network signals are excellent at cutting off simple server traffic, but sophisticated traffic needs a second layer, the browser and behavior. And soft network signals (VPN, IPv6, no ISP) are better not made unconditional. The overall layered protection scheme is in how to filter bots out of ad traffic.

How this is set up in ArtisanClo

In ArtisanClo, network signals are controlled by toggles on the «Filtering» step:

  • Block datacenter ASN cuts hosting and cloud networks that scanners and bots come from.
  • Block VPN/Proxy sharply lowers trust in such visits, since they are used to fake the country.
  • Block IPv6 lowers trust in visits from IPv6; turn it on only if your offer and tracker work over IPv4.
  • Block without ISP lowers trust in visits with no visible ISP.

Note the wording: VPN, IPv6 and no ISP do not drop a visit outright but lower trust. The decision is made on all signals combined, and a single VPN on a real person will not send them to the White Page. The strictness levels enable these checks differently: on «Soft» the network penalties are off, on «Balanced» VPN, proxy and data center checks are on, and «Strict» adds IPv6.

If you need targeted control over networks, the Audience block has Networks (ASN) and Providers lists in «Allowed» or «Denied» mode. A network number is entered as AS15169 or 15169, a provider as it appears in the click log.

The card of every click shows the visit's network: VPN, proxy, data center, ISP. Log reasons such as «VPN or proxy blocked», «High-risk network» and others show exactly which network signal fired. In the statistics, rejections at the network step are grouped under «Network and request». The features page is a convenient place to see what each setting does.

Example: three visits, broken down

To tie it all together, imagine three visits on one link to a German offer. The example is illustrative.

Visit A. A German mobile carrier address, IPv6, a social media in-app browser, German language, Europe/Berlin time zone, a click ID in the link. No network contradictions; IPv6 and an in-app browser are normal for mobile traffic. This is a typical buyer, and soft signals must not cut them off.

Visit B. An address from a cloud hosting network in the Netherlands, the browser claims to be Chrome on Windows, the time zone is UTC, no click ID. Three signals at once: hosting, a foreign country, no ad click. This is a server, whether a scanner, spy tool or review robot, and it belongs on the safe page.

Visit C. A German residential ISP address, but the address is flagged in databases as a residential proxy; the browser time zone is Asian, the system language is not German; no click ID. At the network level the visit looks like a subscriber, but the other signals contradict each other. Here the sum decides: each signal on its own is weak, together they are a confident reason not to show the offer.

The lesson: hard-block what is unambiguous (a hosting network with no ad click), and weigh everything else. That is exactly how trust scoring works in good filters.

Practical recommendations

  1. Keep data center blocking on almost always: it barely touches real people.
  2. Judge VPNs by geo. For countries where VPNs are mainstream, do not make them an unconditional block.
  3. Leave IPv6 alone unless you are sure the whole chain runs over IPv4.
  4. For native and push, watch placements and zones: server fraud concentrates on specific sites, and blocking such a zone in the network itself pays off better than filtering its visits every time. See push and pop traffic.
  5. Add persistent specific addresses to an IP blacklist instead of tightening the whole flow because of them.
  6. Check the log after any change. If the pass rate drops sharply, see which network reason has become frequent.

In short

The IP address tells you which network a visit came from, and the ASN tells you who owns that network. A hosting IP in ad traffic almost always means a server; a VPN or proxy means a faked country or data collection, but sometimes an ordinary person. Network checks catch server traffic well and residential and mobile proxies poorly: those need a second layer of browser checks. Use hard network blocks where an error is unlikely, and a soft penalty where a buyer may be behind the signal.

Frequently asked questions

01

Can you reliably detect a VPN from an IP address?

Not with certainty, but with high probability, yes. The addresses of large VPN services are well known and regularly end up in databases, and the networks hosting them usually belong to hosting companies. Private VPNs on home addresses and residential proxies are harder: there, extra signals such as the browser's time zone and language decide.

02

What is an ASN in simple terms?

An ASN is an autonomous system number, meaning a network run by a single organization: an ISP, a mobile carrier, a hosting company or a large corporation. Every IP address belongs to such a network. Knowing the ASN tells you where a visit came from: a home connection, mobile internet or a server.

03

Should I block all VPN traffic?

It depends on the geo and the offer. In countries where ordinary people use VPNs widely, a blanket block cuts off some buyers. It is safer not to drop VPN visits outright but to lower trust in them and weigh the VPN together with other signals.

04

What is the difference between a residential proxy and a regular one?

A regular proxy runs on a server in a data center, and its address belongs to a hosting network. A residential proxy routes traffic through a home user's address, so at the network level it looks like an ordinary subscriber. It is caught by indirect signs and by browser behavior.

05

Why did a real person get blocked as data center traffic?

It happens with corporate networks, some cloud browsers and data-saving services, where the request to the site goes through the company's server. Check the visit's ISP and network in the log. If that traffic is your target audience, allow that specific network or relax that particular check.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.