Detection

VPN and Tor detection that tells privacy from fraud

VPN detection identifies visitors whose traffic reaches you through a virtual private network, a datacenter exit or the Tor network instead of their own internet connection. Many honest people use VPNs for privacy, so a VPN is a signal, not a verdict. Kavra flags the connection and weighs it with device, behavior and account history.

POST /checkoutAllowed

Privacy VPN, trusted device, normal order

  • Consumer VPN exit
  • Trusted device for 14 months
  • Timezone matches billing country
Risk22
Your actionAllow the order
Who uses them
Privacy-minded customers, remote workers, fraudsters
What they hide
The visitor's real IP address and location
Main risk
Location spoofing and hiding repeat actors
Right response
Weigh by action, never block on VPN alone

What is VPN and Tor detection?

A VPN sends a device's traffic through an encrypted tunnel to a server run by the VPN provider, and the website sees that server's IP address. Most consumer VPN servers sit in data centers, so their exits belong to hosting networks. Tor goes further: it bounces traffic through three volunteer relays, and the site sees only the last one, the exit relay. The Tor Project publishes the list of exit relays, so Tor traffic is easy to recognize.

VPN and Tor detection answers one narrow question: is this visitor reaching you through an anonymizing layer instead of their own connection? It does not answer whether the visitor is honest. That second question needs evidence from the device, the behavior and the account's history.

Types of anonymized connections

"VPN" covers very different traffic. Knowing which kind you see is the first step to handling it well.

ConnectionWho typically uses itHow it is recognizedTypical risk
Consumer VPNPrivacy-minded users, travelers, people on public Wi-FiExit IPs on hosting networks known to belong to VPN providersLow alone, higher with location-based offers
Corporate VPN or security gatewayEmployees working remotelyExits registered to the company or to its security vendorLow: often your best business customers
Self-hosted datacenter exitTechnical users, bots and fraud toolsA cloud or hosting server address with no VPN brand behind itMedium to high, depending on behavior
Apple iCloud Private Relay and similar browser relaysEveryday phone and laptop usersRelay operators publish their exit rangesLow: treat like a normal customer
TorJournalists, activists, privacy researchers, and some attackersTraffic from the public list of Tor exit relaysVaries: common in abuse, but also in legitimate privacy use

Privacy or fraud: why people use VPNs and Tor

Most VPN traffic is ordinary. People turn on a VPN at the airport, keep one running out of habit, use one their employer requires, or live in a country where parts of the web are blocked. Blocking them costs you real customers and support tickets, and it pushes privacy-minded people toward competitors.

Fraudsters use the same tools for different reasons. They want to look like they are somewhere else, and they want to hide that many attempts come from one place.

  • Location spoofing: claiming an offer, price or license that is only available in another country or state.
  • Hiding repeat attempts: signing up or logging in many times without showing the same home IP.
  • Account takeover from abroad: logging in with stolen credentials while appearing to be in the victim's region.
  • Evading bans: returning after a block by appearing from a fresh network.
  • Escalation: when VPN exits get flagged, moving on to residential proxies, which look like home connections.

How VPNs and Tor are detected

No single check is perfect. Good detection combines several independent views of the same connection.

  • Hosting networks

    Most VPN exits live on hosting and cloud networks, which a network lookup by ASN can identify.

  • Known exit lists

    Tor publishes its exit relays, relay services publish their ranges, and commercial VPN exits can be measured directly.

  • Clock and language mismatches

    The device's timezone and language point to one country while the IP address points to another.

  • Signs of a tunnel

    The connection shows an extra hop and properties typical of tunneled traffic, even when the IP address is new.

  • Location jumps

    A returning device appears in a different country from one session to the next, faster than anyone travels.

  • Tor Browser's uniform look

    Tor Browser makes its users look alike on purpose, which is itself recognizable.

A VPN is a signal, not a verdict

Decide by the action and the other evidence. The same VPN user can be fine on one page and worth a check on another.

ActionVPN aloneVPN plus other risk
Browsing and searchAllowAllow, rate-limit clear automation
SignupAllow and record the networkVerify when the device links to other new accounts
Login to a known accountAllow on a trusted deviceStep up on a new device or impossible travel
Promo or bonus claim with a country ruleAllow when device and account fit the countryHold or verify location before paying out
CheckoutAllow when the order and history look normalVerify when billing, device and location disagree
Withdrawal or payoutAllow for long-standing accountsVerify before money leaves

When a stricter VPN or Tor policy makes sense

Some businesses have good reasons to be stricter than "signal, not verdict". The trick is to be strict at the right step, and to tell the customer what to do instead of failing silently.

  • Licensed markets: betting, gaming and some financial products must know the customer's location. Ask users to switch the VPN off at signup, deposit and withdrawal, and let them browse freely.
  • Country-limited offers: when a promotion or price exists only in one region, check that the device, account and payment method fit that region before the reward is paid.
  • Sanctions and compliance: if you must refuse service in certain countries, a hidden location is a reason to verify, not to guess.
  • Repeated abuse from one exit: when a specific VPN server or Tor exit keeps carrying attacks on your login, rate-limit that exit for sensitive actions only.
  • High-value payouts: moving money out is the last point of control. A stricter rule here protects you without touching everyday browsing.

Whatever the policy, show a clear message such as "please turn off your VPN to continue". A silent block looks like a broken site and sends honest customers to support or to a competitor.

Privacy-minded customer vs fraudster on a VPN

Privacy-minded customer

  • Same device and VPN over months
  • Timezone and language fit the account's country
  • Normal pace, typos, reading before clicking
  • One account, consistent billing details

Fraudster on a VPN

  • New device or rotating fingerprint on each visit
  • Location that fits the offer, not the device
  • Scripted or rushed flow straight to the reward
  • Linked to other new accounts or failed logins

Checklist: VPN detection without false positives

Use this list to catch misuse of VPNs and Tor while keeping honest privacy users on board.

  • Tell VPN types apart: consumer VPN, corporate gateway, privacy relay, raw datacenter exit and Tor are not the same risk.
  • Never block on a VPN signal alone. Combine it with device, behavior and account history.
  • Give trusted devices on established accounts the benefit of the doubt, even when the network changes.
  • Put geography rules where geography matters: licensed markets, regional pricing and country-limited offers.
  • Choose verification over blocks for mixed evidence, and keep blocks for clear, multi-layer abuse.
  • Decide your Tor policy per action. Some businesses block Tor at payout; others verify and let people browse.
  • Watch for customers who move from VPN to residential proxy exits after being flagged. That switch says more than either network.
  • Measure your false positives: run rules in observe-only mode and check how many real customers they would stop.

Sources

  1. Tor Project blog: Changes to the Tor Exit List Service
  2. Apple Developer: Prepare your network or web server for iCloud Private Relay
  3. Tor Project: The Design and Implementation of the Tor Browser
  4. RIPE NCC: Autonomous System (AS) Numbers

How Kavra helps

How Kavra handles VPN and Tor traffic

Kavra identifies the network behind every visit and explains how much it should matter for the action at hand.

  • VPN, relay and Tor recognized

    Consumer VPNs, datacenter exits, privacy relays and Tor exits are each labeled, so you know which kind of traffic you are looking at.

  • Own edge network

    Kavra sees the real connection, not only what the browser claims, and compares it with the device and location the browser reports.

  • Measured exits and 30+ feeds

    Kavra measures real exits of commercial proxy networks itself and adds 30+ public reputation feeds for VPN, hosting and Tor ranges.

  • History beats geography

    Logins are compared with the account's own trusted devices and usual networks, so a loyal VPN user is not treated as a stranger.

  • Signal, not verdict

    The AI/ML risk engine weighs the network with device, behavior and identity, and policy presets let you choose cautious, balanced or strict.

  • No puzzles for real customers

    When evidence is mixed, invisible challenges run first, so privacy users rarely see any friction at all.

FAQ

Frequently asked questions

Something else? Talk to our team.

Can websites tell if I am using a VPN?

Often, yes. Most consumer VPN servers run in data centers, and their exit addresses can be matched to hosting networks and known VPN ranges. Sites can also compare the device's timezone and language with the IP location. Detecting a VPN does not mean the site will block you; many only use it as one input among many.

Should I block VPN users on my website?

In most cases, no. Many honest customers use VPNs for privacy, work or public Wi-Fi, so blanket blocks cost revenue and trust. Block or verify only where geography is part of the rule, such as licensed markets or country-limited offers, or where the VPN appears together with other risk signals like a new device or linked accounts.

Why do banks and betting sites block VPNs?

Many are legally required to know where a customer is, for example to serve only licensed markets or to meet anti-money laundering rules. A VPN hides that location, so these businesses often ask users to turn it off at key moments like signup, deposit or withdrawal, even if browsing with a VPN is fine.

How is Tor traffic detected?

The Tor Project publishes the list of its exit relays, so a site can check whether a visit comes from one of them. Tor Browser also makes its users look deliberately alike, which is recognizable. Detection is reliable; the harder choice is policy: whether to allow, verify or block Tor at each step.

Does iCloud Private Relay count as a VPN?

It works like a relay rather than a full VPN, and Apple publishes the address ranges its relays use. Traffic from it comes mostly from ordinary iPhone, iPad and Mac users with the feature turned on. Treat it as a normal customer connection with a less precise location, not as a fraud signal.

Can a VPN hide fraud from detection tools?

It hides the real IP address, and nothing more. The device, the browser, how the person types and clicks, and the account's history all remain visible. That is why fraudsters pair VPNs with antidetect browsers and proxies, and why detection that compares several layers still finds the actor behind the tunnel.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.