one check

Proxy detection test

Five things a site can read about your connection, and whether any of them points to a proxy or VPN.

Collecting the signals a site can read

How do websites detect a proxy or VPN?

They compare what the connection says with what the browser says: the kind of network behind the address, the time zone against where the address sits, the address WebRTC reveals, the TCP handshake against the operating system the browser names, and headers a proxy adds on the way. On top of that most bot checks keep a record of what each address has done before.

Why does a datacenter address give me away?

People browse from home and mobile lines, while addresses of hosting companies belong to servers. Most sites therefore treat a datacenter address as a proxy, a VPN or a bot before they look at anything else.

What is a WebRTC leak?

WebRTC opens its own connection for calls and file transfers. When that connection goes around the proxy, the site sees a second public address, usually the real one, and the WebRTC check lists every candidate it found.

Can a residential or mobile proxy be detected?

Not from the address alone: free datasets cannot tell a residential proxy from an ordinary home line, which is why this page never claims one. What still gives one away is inconsistency, such as a clock set to another country or a server's TCP stack under a Windows browser, and the history the address already has at the site.

Does my DNS resolver matter here?

An ordinary website cannot see which resolver you use, so it is not a detection signal. Whether your lookups go around the tunnel is a privacy question, answered by the DNS leak test.

What this one page cannot tell you

The reputation of your address, the record a site keeps of what it has already seen from it, lives in their systems and cannot be measured here.

The interesting part is usually not a single value but the disagreement between two. The full check reads all five layers and shows you where they contradict each other.