POST /checkoutAllowedPrivacy VPN, trusted device, normal order
- Consumer VPN exit
- Trusted device for 14 months
- Timezone matches billing country
Detection
VPN detection identifies visitors whose traffic reaches you through a virtual private network, a datacenter exit or the Tor network instead of their own internet connection. Many honest people use VPNs for privacy, so a VPN is a signal, not a verdict. Kavra flags the connection and weighs it with device, behavior and account history.
POST /checkoutAllowedPrivacy VPN, trusted device, normal order
A VPN sends a device's traffic through an encrypted tunnel to a server run by the VPN provider, and the website sees that server's IP address. Most consumer VPN servers sit in data centers, so their exits belong to hosting networks. Tor goes further: it bounces traffic through three volunteer relays, and the site sees only the last one, the exit relay. The Tor Project publishes the list of exit relays, so Tor traffic is easy to recognize.
VPN and Tor detection answers one narrow question: is this visitor reaching you through an anonymizing layer instead of their own connection? It does not answer whether the visitor is honest. That second question needs evidence from the device, the behavior and the account's history.
"VPN" covers very different traffic. Knowing which kind you see is the first step to handling it well.
| Connection | Who typically uses it | How it is recognized | Typical risk |
|---|---|---|---|
| Consumer VPN | Privacy-minded users, travelers, people on public Wi-Fi | Exit IPs on hosting networks known to belong to VPN providers | Low alone, higher with location-based offers |
| Corporate VPN or security gateway | Employees working remotely | Exits registered to the company or to its security vendor | Low: often your best business customers |
| Self-hosted datacenter exit | Technical users, bots and fraud tools | A cloud or hosting server address with no VPN brand behind it | Medium to high, depending on behavior |
| Apple iCloud Private Relay and similar browser relays | Everyday phone and laptop users | Relay operators publish their exit ranges | Low: treat like a normal customer |
| Tor | Journalists, activists, privacy researchers, and some attackers | Traffic from the public list of Tor exit relays | Varies: common in abuse, but also in legitimate privacy use |
Most VPN traffic is ordinary. People turn on a VPN at the airport, keep one running out of habit, use one their employer requires, or live in a country where parts of the web are blocked. Blocking them costs you real customers and support tickets, and it pushes privacy-minded people toward competitors.
Fraudsters use the same tools for different reasons. They want to look like they are somewhere else, and they want to hide that many attempts come from one place.
No single check is perfect. Good detection combines several independent views of the same connection.
Most VPN exits live on hosting and cloud networks, which a network lookup by ASN can identify.
Tor publishes its exit relays, relay services publish their ranges, and commercial VPN exits can be measured directly.
The device's timezone and language point to one country while the IP address points to another.
The connection shows an extra hop and properties typical of tunneled traffic, even when the IP address is new.
A returning device appears in a different country from one session to the next, faster than anyone travels.
Tor Browser makes its users look alike on purpose, which is itself recognizable.
Decide by the action and the other evidence. The same VPN user can be fine on one page and worth a check on another.
| Action | VPN alone | VPN plus other risk |
|---|---|---|
| Browsing and search | Allow | Allow, rate-limit clear automation |
| Signup | Allow and record the network | Verify when the device links to other new accounts |
| Login to a known account | Allow on a trusted device | Step up on a new device or impossible travel |
| Promo or bonus claim with a country rule | Allow when device and account fit the country | Hold or verify location before paying out |
| Checkout | Allow when the order and history look normal | Verify when billing, device and location disagree |
| Withdrawal or payout | Allow for long-standing accounts | Verify before money leaves |
Some businesses have good reasons to be stricter than "signal, not verdict". The trick is to be strict at the right step, and to tell the customer what to do instead of failing silently.
Whatever the policy, show a clear message such as "please turn off your VPN to continue". A silent block looks like a broken site and sends honest customers to support or to a competitor.
Use this list to catch misuse of VPNs and Tor while keeping honest privacy users on board.
How Kavra helps
Kavra identifies the network behind every visit and explains how much it should matter for the action at hand.
Consumer VPNs, datacenter exits, privacy relays and Tor exits are each labeled, so you know which kind of traffic you are looking at.
Kavra sees the real connection, not only what the browser claims, and compares it with the device and location the browser reports.
Kavra measures real exits of commercial proxy networks itself and adds 30+ public reputation feeds for VPN, hosting and Tor ranges.
Logins are compared with the account's own trusted devices and usual networks, so a loyal VPN user is not treated as a stranger.
The AI/ML risk engine weighs the network with device, behavior and identity, and policy presets let you choose cautious, balanced or strict.
When evidence is mixed, invisible challenges run first, so privacy users rarely see any friction at all.
FAQ
Something else? Talk to our team.
Often, yes. Most consumer VPN servers run in data centers, and their exit addresses can be matched to hosting networks and known VPN ranges. Sites can also compare the device's timezone and language with the IP location. Detecting a VPN does not mean the site will block you; many only use it as one input among many.
In most cases, no. Many honest customers use VPNs for privacy, work or public Wi-Fi, so blanket blocks cost revenue and trust. Block or verify only where geography is part of the rule, such as licensed markets or country-limited offers, or where the VPN appears together with other risk signals like a new device or linked accounts.
Many are legally required to know where a customer is, for example to serve only licensed markets or to meet anti-money laundering rules. A VPN hides that location, so these businesses often ask users to turn it off at key moments like signup, deposit or withdrawal, even if browsing with a VPN is fine.
The Tor Project publishes the list of its exit relays, so a site can check whether a visit comes from one of them. Tor Browser also makes its users look deliberately alike, which is recognizable. Detection is reliable; the harder choice is policy: whether to allow, verify or block Tor at each step.
It works like a relay rather than a full VPN, and Apple publishes the address ranges its relays use. Traffic from it comes mostly from ordinary iPhone, iPad and Mac users with the feature turned on. Treat it as a normal customer connection with a less precise location, not as a fraud signal.
It hides the real IP address, and nothing more. The device, the browser, how the person types and clicks, and the account's history all remain visible. That is why fraudsters pair VPNs with antidetect browsers and proxies, and why detection that compares several layers still finds the actor behind the tunnel.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.