VPN Detection API — Know Which VPN a Visitor Is On
Maskbreak tells you whether a visitor is on a VPN, proxy or Tor and names the service when it is known, using live network intelligence on hundreds of VPN and proxy services. Pick a country below for what to expect from its traffic.
VPN & proxy detection — jump to a country
What the network looks like, country by country
The datacenter and ISP concentrations below are what actually differ between markets. Two patterns hold almost everywhere and are worth stating once rather than thirty times.
Residential proxy resale. Consumer ISP ranges in any country can appear in commercial or peer-to-peer residential proxy pools. A consumer ISP label is not proof of fraud — combine it with device, session and routing signals before acting on it.
Antidetect browser usage. Multi-accounting fraud against SaaS, fintech and e-commerce increasingly runs through Kameleo, GoLogin or AdsPower to spoof device fingerprints. Maskbreak scores those at the device layer, not the IP layer, so they are caught regardless of which country the address resolves to.
Argentina
Argentina is a top regional source of residential-proxy-masked subscription fraud, particularly Telecentro and Claro ranges.
Australia
Vultr Sydney and Linode Sydney datacenter ranges generate most fraudulent SaaS signups, despite a comparatively small VPN market.
Belgium
Proximus and Telenet consumer ranges are cycled through residential proxy networks to bypass EU geofencing.
Brazil
Brazil is one of the world's largest residential proxy markets, primarily Vivo and Claro consumer ranges.
Canada
OVH's Beauharnois datacenter ASN is a top origin of cross-border SaaS account abuse targeting Canadian platforms.
Denmark
VPN density is low, but TDC consumer ranges are increasingly cycled through paid residential proxy networks.
Estonia
Estonia's e-residency programme draws crypto and fintech business from around the world — a small market with a high concentration of crypto-targeted VPN traffic via Telia and Elisa ranges.
Finland
Hetzner Helsinki and UpCloud datacenter ranges drive nearly all Finnish VPN exit traffic.
France
OVH-hosted residential proxy services account for a disproportionate share of fraudulent traffic into French SaaS platforms.
Germany
Hetzner, OVH, and Contabo datacenter ranges host the largest VPN exit node concentration in the EU.
India
Low-cost residential proxies sourced from Jio and Airtel consumer connections operate at massive scale.
Ireland
AWS Dublin and Microsoft Azure Dublin are the largest datacenter VPN exit sources in Western Europe.
Israel
Datacenter ASN concentration is heavy — Bezeq International and Cellcom ranges are the most commonly resold as proxies.
Italy
TIM and Vodafone consumer IPs are cycled through residential proxy networks for ad fraud at a high rate.
Japan
NTT and SoftBank residential ranges are the most common origin for Asia-targeted SaaS fraud.
Mexico
Telmex consumer IPs are heavily abused in residential proxy networks targeting US-facing SaaS platforms.
Netherlands
The Netherlands is Europe's most VPN-saturated country per capita — most paid VPN providers run their primary EU exits here.
Norway
The VPN footprint is small and dominated by Telenor consumer ranges resold via residential proxy services.
Poland
Antidetect-browser-driven account fraud is growing rapidly, primarily via Orange Polska consumer ranges.
Portugal
A rising residential-proxy market centres on MEO and NOS consumer ranges sold to ad-fraud operators.
Singapore
Singapore is a major regional VPN exit hub — DigitalOcean SGP1 and Vultr Singapore generate the bulk of Asia-Pacific VPN traffic.
South Africa
Telkom SA and Vumatel ranges are increasingly resold via residential proxy services targeting fintech.
South Korea
Gaming and crypto fraud are particularly active, with KT and SK Broadband ranges the most often abused.
Spain
Residential proxy abuse is rising rapidly, particularly via Movistar and Vodafone consumer ranges resold by botnets.
Sweden
Mullvad VPN is headquartered here, and privacy-focused VPN exit nodes cluster in Bahnhof and FS Data ranges.
Switzerland
Switzerland is home to ProtonVPN — Swiss exit nodes carry an unusually high share of legitimate privacy traffic mixed with fraud.
Turkey
Türk Telekom and Turkcell consumer ranges fuel a significant share of bypass-driven VPN traffic into the EU.
United Arab Emirates
VPN usage to bypass local restrictions is high — Etisalat and du IPs frequently appear in privacy-driven VPN traffic.
United Kingdom
The UK has one of the highest VPN penetration rates in Europe, with M247, Datacamp, and Hostpalace ranges driving most VPN traffic.
United States
A high concentration of datacenter ASNs (AWS, Google Cloud, DigitalOcean) is routinely used for credential stuffing and trial abuse.
One API. Every country. Every threat.
Free tier: 1,000 requests/hour. No card, no expiry. Real-time VPN, residential proxy, datacenter ASN, and bot detection with global coverage.
Run your own connection through the live scanner
Flip your VPN on and off and watch the verdict change in real time — no signup needed. Want to check a specific address for Tor or datacenter origin? Use the free IP lookup. For repeatable integration checks, use the VPN detection API test cases guide.
VPN detection, answered
How does VPN detection work?
Maskbreak inspects every request against continuously updated intelligence on commercial VPN ranges, datacenter ASNs, and Tor exit nodes, and layers device and behavioural signals on a live session to expose residential-proxy and antidetect traffic a plain IP feed misses. Each visitor is scored in under 150ms server-side — without blocking legitimate users.
Can Maskbreak detect residential proxies?
Yes. Residential proxies — including commercial and peer-to-peer residential networks — are detected through Maskbreak’s own network intelligence evaluated on the live session, layered with device fingerprinting and each device's per-customer history with your app. Treat the result as one risk signal and validate it against your own traffic.
Which countries are covered?
Maskbreak provides country-specific intelligence for 30+ jurisdictions including the United States, United Kingdom, Germany, France, India, Brazil, Japan, South Korea, UAE, Australia, and every EU member state. Coverage extends to every IANA-assigned IP range globally.
How fast is the detection API?
Server decision time is under 150ms at the median, and Cloudflare's global edge network fronts the API — the scanner's first-pass verdict is answered directly at the edge.
Is there a free tier?
Yes, and it is the only tier. 1,000 requests/hour, every signal, no card and no expiry. If you need sustained volume above that, write to us.
Does VPN detection block privacy-conscious users?
No. A VPN on its own comes back as review, not block. Every response carries allow / review / block plus the score and the individual signals, and your code sets the final policy: many platforms allow VPN traffic on public pages and step up verification at signup or checkout. This removes fraud without alienating privacy-aware customers.