Resources Docs Free Blog Contact
Log inGet started
VPN Detection

VPN Detection API — Know Which VPN a Visitor Is On

Maskbreak tells you whether a visitor is on a VPN, proxy or Tor and names the service when it is known, using live network intelligence on hundreds of VPN and proxy services.

Detection reads the connection, not the country

There is no per-country setup and no coverage list: a visit is checked by how it connects and what the browser shows, wherever it comes from. Two patterns hold in every market.

Residential proxy resale. Consumer ISP ranges in any country can appear in commercial or peer-to-peer residential proxy pools. A consumer ISP label is not proof of fraud — combine it with device, session and routing signals before acting on it.

Antidetect browser usage. Multi-accounting fraud against SaaS, fintech and e-commerce increasingly runs through Kameleo, GoLogin or AdsPower to spoof device fingerprints. Maskbreak scores those at the device layer, not the IP layer, so they are caught regardless of which country the address resolves to.

One check before every signup, login and checkout.

Free during open beta: 1,000 visitor checks/hour per API key. No card. At least 30 days’ notice before paid changes. Real-time VPN, residential proxy, datacenter ASN, and bot detection with global coverage.

Run your own connection through the live scanner

Flip your VPN on and off and watch the verdict change in real time — no signup needed. Want to check a specific address for Tor or datacenter origin? Use the free IP lookup. For repeatable integration checks, use the VPN detection API test cases guide.

Scan my connection Free IP lookup

VPN detection, answered

How does VPN detection work?

Maskbreak inspects every request against continuously updated intelligence on commercial VPN ranges, datacenter ASNs, and Tor exit nodes, and layers device and behavioural signals on a live session to expose residential-proxy and antidetect traffic a plain IP feed misses. Each visitor is scored in under 150ms server-side — without blocking legitimate users.

Can Maskbreak detect residential proxies?

Yes. Residential proxies — including commercial and peer-to-peer residential networks — are detected through Maskbreak’s own network intelligence evaluated on the live session, layered with device fingerprinting and each device's per-customer history with your app. Treat the result as one risk signal and validate it against your own traffic.

Which countries are covered?

All of them, with no per-country setup. Maskbreak reads the connection and the browser of each visit, so a VPN, proxy or Tor exit is recognised wherever the visitor is, and the service is named when it is known.

How fast is the detection API?

Server decision time is under 150ms at the median, and Cloudflare's global edge network fronts the API — the scanner's first-pass verdict is answered directly at the edge.

Is there a free tier?

Yes. Free during open beta: 1,000 visitor checks/hour per API key. No card. At least 30 days’ notice before paid changes. If you need sustained volume above that, write to us.

Does VPN detection block privacy-conscious users?

No. A VPN on its own comes back as review, not block. Every response carries allow / review / block plus the score and the individual signals, and your code sets the final policy: many platforms allow VPN traffic on public pages and step up verification at signup or checkout. This removes fraud without alienating privacy-aware customers.

Stop fraud before it hides — try Maskbreak free. Free during open beta: 1,000 visitor checks/hour per API key. No card. At least 30 days’ notice before paid changes.