Resources Docs Free Blog Contact
Log inGet started
VPN Detection by Country

VPN Detection API — Know Which VPN a Visitor Is On

Maskbreak tells you whether a visitor is on a VPN, proxy or Tor and names the service when it is known, using live network intelligence on hundreds of VPN and proxy services. Pick a country below for what to expect from its traffic.

VPN & proxy detection — jump to a country

United States United Kingdom Germany France Netherlands Spain Italy Canada Australia Brazil India Japan South Korea Singapore Sweden Switzerland Norway Denmark Finland Poland Mexico Argentina Turkey South Africa United Arab Emirates Israel Ireland Portugal Belgium Estonia

What the network looks like, country by country

The datacenter and ISP concentrations below are what actually differ between markets. Two patterns hold almost everywhere and are worth stating once rather than thirty times.

Residential proxy resale. Consumer ISP ranges in any country can appear in commercial or peer-to-peer residential proxy pools. A consumer ISP label is not proof of fraud — combine it with device, session and routing signals before acting on it.

Antidetect browser usage. Multi-accounting fraud against SaaS, fintech and e-commerce increasingly runs through Kameleo, GoLogin or AdsPower to spoof device fingerprints. Maskbreak scores those at the device layer, not the IP layer, so they are caught regardless of which country the address resolves to.

Argentina

Argentina is a top regional source of residential-proxy-masked subscription fraud, particularly Telecentro and Claro ranges.

Australia

Vultr Sydney and Linode Sydney datacenter ranges generate most fraudulent SaaS signups, despite a comparatively small VPN market.

Belgium

Proximus and Telenet consumer ranges are cycled through residential proxy networks to bypass EU geofencing.

Brazil

Brazil is one of the world's largest residential proxy markets, primarily Vivo and Claro consumer ranges.

Canada

OVH's Beauharnois datacenter ASN is a top origin of cross-border SaaS account abuse targeting Canadian platforms.

Denmark

VPN density is low, but TDC consumer ranges are increasingly cycled through paid residential proxy networks.

Estonia

Estonia's e-residency programme draws crypto and fintech business from around the world — a small market with a high concentration of crypto-targeted VPN traffic via Telia and Elisa ranges.

Finland

Hetzner Helsinki and UpCloud datacenter ranges drive nearly all Finnish VPN exit traffic.

France

OVH-hosted residential proxy services account for a disproportionate share of fraudulent traffic into French SaaS platforms.

Germany

Hetzner, OVH, and Contabo datacenter ranges host the largest VPN exit node concentration in the EU.

India

Low-cost residential proxies sourced from Jio and Airtel consumer connections operate at massive scale.

Ireland

AWS Dublin and Microsoft Azure Dublin are the largest datacenter VPN exit sources in Western Europe.

Israel

Datacenter ASN concentration is heavy — Bezeq International and Cellcom ranges are the most commonly resold as proxies.

Italy

TIM and Vodafone consumer IPs are cycled through residential proxy networks for ad fraud at a high rate.

Japan

NTT and SoftBank residential ranges are the most common origin for Asia-targeted SaaS fraud.

Mexico

Telmex consumer IPs are heavily abused in residential proxy networks targeting US-facing SaaS platforms.

Netherlands

The Netherlands is Europe's most VPN-saturated country per capita — most paid VPN providers run their primary EU exits here.

Norway

The VPN footprint is small and dominated by Telenor consumer ranges resold via residential proxy services.

Poland

Antidetect-browser-driven account fraud is growing rapidly, primarily via Orange Polska consumer ranges.

Portugal

A rising residential-proxy market centres on MEO and NOS consumer ranges sold to ad-fraud operators.

Singapore

Singapore is a major regional VPN exit hub — DigitalOcean SGP1 and Vultr Singapore generate the bulk of Asia-Pacific VPN traffic.

South Africa

Telkom SA and Vumatel ranges are increasingly resold via residential proxy services targeting fintech.

South Korea

Gaming and crypto fraud are particularly active, with KT and SK Broadband ranges the most often abused.

Spain

Residential proxy abuse is rising rapidly, particularly via Movistar and Vodafone consumer ranges resold by botnets.

Sweden

Mullvad VPN is headquartered here, and privacy-focused VPN exit nodes cluster in Bahnhof and FS Data ranges.

Switzerland

Switzerland is home to ProtonVPN — Swiss exit nodes carry an unusually high share of legitimate privacy traffic mixed with fraud.

Turkey

Türk Telekom and Turkcell consumer ranges fuel a significant share of bypass-driven VPN traffic into the EU.

United Arab Emirates

VPN usage to bypass local restrictions is high — Etisalat and du IPs frequently appear in privacy-driven VPN traffic.

United Kingdom

The UK has one of the highest VPN penetration rates in Europe, with M247, Datacamp, and Hostpalace ranges driving most VPN traffic.

United States

A high concentration of datacenter ASNs (AWS, Google Cloud, DigitalOcean) is routinely used for credential stuffing and trial abuse.

One API. Every country. Every threat.

Free tier: 1,000 requests/hour. No card, no expiry. Real-time VPN, residential proxy, datacenter ASN, and bot detection with global coverage.

Run your own connection through the live scanner

Flip your VPN on and off and watch the verdict change in real time — no signup needed. Want to check a specific address for Tor or datacenter origin? Use the free IP lookup. For repeatable integration checks, use the VPN detection API test cases guide.

[ Scan my connection ] [ Free IP lookup ]

VPN detection, answered

How does VPN detection work?

Maskbreak inspects every request against continuously updated intelligence on commercial VPN ranges, datacenter ASNs, and Tor exit nodes, and layers device and behavioural signals on a live session to expose residential-proxy and antidetect traffic a plain IP feed misses. Each visitor is scored in under 150ms server-side — without blocking legitimate users.

Can Maskbreak detect residential proxies?

Yes. Residential proxies — including commercial and peer-to-peer residential networks — are detected through Maskbreak’s own network intelligence evaluated on the live session, layered with device fingerprinting and each device's per-customer history with your app. Treat the result as one risk signal and validate it against your own traffic.

Which countries are covered?

Maskbreak provides country-specific intelligence for 30+ jurisdictions including the United States, United Kingdom, Germany, France, India, Brazil, Japan, South Korea, UAE, Australia, and every EU member state. Coverage extends to every IANA-assigned IP range globally.

How fast is the detection API?

Server decision time is under 150ms at the median, and Cloudflare's global edge network fronts the API — the scanner's first-pass verdict is answered directly at the edge.

Is there a free tier?

Yes, and it is the only tier. 1,000 requests/hour, every signal, no card and no expiry. If you need sustained volume above that, write to us.

Does VPN detection block privacy-conscious users?

No. A VPN on its own comes back as review, not block. Every response carries allow / review / block plus the score and the individual signals, and your code sets the final policy: many platforms allow VPN traffic on public pages and step up verification at signup or checkout. This removes fraud without alienating privacy-aware customers.

Stop fraud before it hides — try Maskbreak free. Free tier: 1,000 requests/hour. No card, no expiry.