How a VPN works
When a VPN is switched on, the app on the device creates an encrypted connection to a VPN server using a protocol such as WireGuard or OpenVPN. From then on, every request from the device travels inside that tunnel. The internet provider or the café Wi-Fi sees only encrypted traffic going to the VPN server. The VPN server decrypts it and sends it on to the websites, which see the server's IP address.
Consumer VPN providers run servers in many countries, so a user in one city can appear to be in another with a click. Business VPNs work the same way but connect employees to the company network. Most VPN servers sit in data centers, and one server IP is shared by many customers at once.
VPN vs proxy
Both hide the real IP address. They differ in scope, encryption and where the exit lives.
| VPN | Proxy | |
|---|---|---|
| What it covers | All traffic from the device | Usually one app or browser profile |
| Encryption to the server | Yes, always | Often none beyond the site's own HTTPS |
| Typical exit IP | A hosting provider's data center | Datacenter, residential or mobile, depending on type |
| How it is sold | Monthly subscription, apps for every device | Per IP, per port or per gigabyte |
| Main users | Privacy-minded consumers, remote staff | Scrapers, marketers, automation tools |
| How easy to spot | Moderate, known server ranges | Easy for datacenter, hard for residential |
VPNs in real traffic and in fraud
Most VPN users are not fraudsters. People turn on a VPN on hotel Wi-Fi, to protect their privacy, to reach content from home while traveling, or because their employer requires it. Treating every VPN visitor as a threat causes false positives and angry customers.
In fraud, a VPN usually does one job: hiding location. It helps a bettor appear to be in a licensed region, a buyer appear local to get a regional price, or an attacker appear to be in the same country as the victim during account takeover. VPNs are a weak disguise for volume attacks, since a provider has a limited set of server IPs, so large campaigns usually move to residential proxies instead.
- Location clues disagree: device timezone and language point to one country, the VPN exit to another.
- New network on an old account: a login from a VPN exit the account owner has never used.
- Geo-restricted actions: signups, deposits or purchases that depend on region.
- Shared exit: many unrelated accounts appear from the same VPN server in a short time.
How to detect VPN traffic fairly
VPN detection starts with knowing which IPs belong to VPN providers, from provider server lists and hosting ranges. It gets stronger when the network is compared with the device, for example a timezone that does not match the exit country, or connection timing that shows the traffic is relayed. The decision should depend on the action: a VPN on a product page means little, a VPN on a withdrawal from a new device means more.
Kavra identifies VPN, Tor and proxy traffic on every visit through its own edge network and reputation data, then weighs it with device, behavior and account history so that privacy-minded customers are not blocked by default. See VPN and Tor detection.