Network signals are the first thing any traffic filter sees and the cheapest to check: before the page even loads, you know which address the visit came from and who owns it. That is why VPN, proxy and data center IP detection sits at the base of almost every bot protection setup. It is also where real people are easiest to block by mistake if you do not understand how these signals work.
How an IP address works: networks, ISPs, ASN
The internet is made up of many networks, each run by a single organization. Such a network is called an autonomous system, and its number is the ASN (for example, AS15169). Every public IP address belongs to some autonomous system.
Based on the ASN and network owner data, addresses fall into several types:
| Network type | Owner | Who usually comes from it |
|---|---|---|
| Residential ISP | internet service provider | ordinary users on Wi-Fi |
| Mobile carrier | cellular company | smartphone users |
| Hosting, cloud, data center | hosting companies and cloud platforms | servers, scripts, VPNs, proxies, scanners |
| Corporate network | company or institution | employees behind a shared exit |
| Educational network | university | students, staff |
For advertising, the key distinction is simple: a real person goes online through an ISP or a carrier, while a program runs on a server. A visit from a cloud hosting network on an ad link almost always means automation.
Where IP data comes from
Which network an address belongs to is public: it is visible in internet address registries and routing tables. On top of that, specialized databases collect extra details: network type, ISP, geolocation, and signs of VPNs, proxies and anonymization nodes. No database is perfect, since addresses get resold and networks change purpose, so good filters use them as one signal among many, not as a final verdict.
Data center IP detection: how hosting IPs are identified
A hosting IP is an address that belongs to a cloud platform, VPS provider or data center. It is identified:
- By ASN. The networks of major clouds and hosting providers are known and stable.
- By range owner. The range's registration data names a hosting or cloud company.
- By the lack of a subscriber ISP. A server address often has no recognizable consumer ISP, which is a sign in itself.
- By observation. If bots keep coming from a network's addresses, the network earns a bad reputation. More in IP reputation.
Blocking data center ASNs is one of the most effective measures against scanners, scrapers and spy tools, covered in detail in protection from spy tools. It rarely hits real people, but it does: cloud browsers and some corporate exits also run on servers.
VPN detection
A VPN encrypts traffic and sends it out to the internet through the VPN provider's server. To the site, the visit looks as if it came from that server. Signs of a VPN:
- The address is in a database of known VPN nodes. Large commercial VPNs use thousands of addresses, and they become known quickly.
- A hosting network. Most VPN servers sit in data centers.
- Inconsistency with the browser. The system time zone says Moscow while the IP is in the Netherlands; the browser language is Vietnamese while the geo is Germany.
- Real address leaks. Sometimes the browser exposes the real address through separate connection channels, and it does not match the request address.
Who uses a VPN
Scrapers, spy tools and ordinary people all come through VPNs. The share of ordinary people depends heavily on the country: in some places a VPN is exotic, in others it is everyday. So a blanket VPN block is a decision for a specific geo and offer, not a default setting. It is safer to lower trust in the visit and weigh the VPN together with other signals.
Proxy detection
A proxy is an intermediary the request goes through. There are several kinds, and each is detected differently.
Server proxies
They run in data centers, so they give themselves away just like hosting IPs. Some proxies also add service headers to the request that reveal them immediately.
Residential proxies
Traffic exits through the address of an ordinary home user, most often via an app the user installed without reading the terms. At the network level such a visit is indistinguishable from a subscriber. Residential proxies are detected indirectly:
- the address shows up in databases as seen proxying;
- the browser's behavior does not match what is expected from that network and geo;
- visits with different browser fingerprints come from the address within a short time.
Mobile proxies
They work through mobile carrier SIM cards. They are especially hard to cut off: hundreds of real subscribers already share one mobile address, and blocking the whole address means cutting live traffic.
Tip. Network checks are nearly powerless against residential and mobile proxies. What works there are browser and behavior checks, covered in headless browsers and browser fingerprinting.
IPv6 and visits without an ISP
Two related signals that are often turned on by mistake.
- IPv6. Many mobile carriers give subscribers IPv6 addresses, so blocking IPv6 can cut a big chunk of mobile traffic. It is justified only if both your offer and your tracker work over IPv4.
- No ISP. If an address has no identifiable ISP, it is usually a server. For most platforms the signal is useful, but for part of TikTok traffic, for example, it causes false positives.
Where network filtering gets it wrong
| Situation | What the filter sees | What it really is |
|---|---|---|
| Office employee | corporate network, many visits from one address | a real person |
| Cloud browser or data saver | the company's server address | a real person |
| Traveler | roaming, a «foreign» geo, mismatched time zone | a real person |
| Residential proxy | residential ISP | a bot or spy tool |
| Mobile proxy | mobile carrier | a bot or account farm |
The takeaway: network signals are excellent at cutting off simple server traffic, but sophisticated traffic needs a second layer, the browser and behavior. And soft network signals (VPN, IPv6, no ISP) are better not made unconditional. The overall layered protection scheme is in how to filter bots out of ad traffic.
How this is set up in ArtisanClo
In ArtisanClo, network signals are controlled by toggles on the «Filtering» step:
- Block datacenter ASN cuts hosting and cloud networks that scanners and bots come from.
- Block VPN/Proxy sharply lowers trust in such visits, since they are used to fake the country.
- Block IPv6 lowers trust in visits from IPv6; turn it on only if your offer and tracker work over IPv4.
- Block without ISP lowers trust in visits with no visible ISP.
Note the wording: VPN, IPv6 and no ISP do not drop a visit outright but lower trust. The decision is made on all signals combined, and a single VPN on a real person will not send them to the White Page. The strictness levels enable these checks differently: on «Soft» the network penalties are off, on «Balanced» VPN, proxy and data center checks are on, and «Strict» adds IPv6.
If you need targeted control over networks, the Audience block has Networks (ASN) and Providers lists in «Allowed» or «Denied» mode. A network number is entered as AS15169 or 15169, a provider as it appears in the click log.
The card of every click shows the visit's network: VPN, proxy, data center, ISP. Log reasons such as «VPN or proxy blocked», «High-risk network» and others show exactly which network signal fired. In the statistics, rejections at the network step are grouped under «Network and request». The features page is a convenient place to see what each setting does.
Example: three visits, broken down
To tie it all together, imagine three visits on one link to a German offer. The example is illustrative.
Visit A. A German mobile carrier address, IPv6, a social media in-app browser, German language, Europe/Berlin time zone, a click ID in the link. No network contradictions; IPv6 and an in-app browser are normal for mobile traffic. This is a typical buyer, and soft signals must not cut them off.
Visit B. An address from a cloud hosting network in the Netherlands, the browser claims to be Chrome on Windows, the time zone is UTC, no click ID. Three signals at once: hosting, a foreign country, no ad click. This is a server, whether a scanner, spy tool or review robot, and it belongs on the safe page.
Visit C. A German residential ISP address, but the address is flagged in databases as a residential proxy; the browser time zone is Asian, the system language is not German; no click ID. At the network level the visit looks like a subscriber, but the other signals contradict each other. Here the sum decides: each signal on its own is weak, together they are a confident reason not to show the offer.
The lesson: hard-block what is unambiguous (a hosting network with no ad click), and weigh everything else. That is exactly how trust scoring works in good filters.
Practical recommendations
- Keep data center blocking on almost always: it barely touches real people.
- Judge VPNs by geo. For countries where VPNs are mainstream, do not make them an unconditional block.
- Leave IPv6 alone unless you are sure the whole chain runs over IPv4.
- For native and push, watch placements and zones: server fraud concentrates on specific sites, and blocking such a zone in the network itself pays off better than filtering its visits every time. See push and pop traffic.
- Add persistent specific addresses to an IP blacklist instead of tightening the whole flow because of them.
- Check the log after any change. If the pass rate drops sharply, see which network reason has become frequent.
In short
The IP address tells you which network a visit came from, and the ASN tells you who owns that network. A hosting IP in ad traffic almost always means a server; a VPN or proxy means a faked country or data collection, but sometimes an ordinary person. Network checks catch server traffic well and residential and mobile proxies poorly: those need a second layer of browser checks. Use hard network blocks where an error is unlikely, and a soft penalty where a buyer may be behind the signal.



