When a site decides your IP is "a VPN" or "a proxy," it's rarely a guess. Modern anti-bot systems run a stack of checks the moment you connect, and most of them come down to two questions: what network does this IP live on, and is it already on a known-proxy list? Here's how that actually works.

How websites detect that an IP belongs to a VPN or proxy

The first check: what network does the IP live on?

Every IP belongs to an ASN — the network that owns it. That single fact gives most of the game away:

  • Datacenter / hosting ASNs (AWS, OVH, DigitalOcean, Hetzner…) are public and well-known. No real person browses from a server farm, so an IP on one of these ranges screams "VPN or proxy" instantly.
  • Consumer ISP ASNs (Comcast, Vodafone, Deutsche Telekom…) are what real homes sit behind — those blend in.

This is the core reason datacenter proxies get caught fastest and residential ones are hard to track: the ASN alone flags the former. (More on what reads as a home IP in what makes an IP look residential.)

The big one: third-party proxy/VPN databases

Here's the part most people miss. Most sites don't build detection themselves — anti-bot detection is supplied by third-party providers (think IPQualityScore, MaxMind, IP2Proxy and the big anti-bot vendors) that maintain massive, constantly-updated databases of known VPN, proxy and datacenter IPs.

When you connect, your IP is matched against that database. If it's listed, you're flagged before the page even loads. And these systems don't sit still: they run machine-learning models that keep learning — new proxy ranges, new patterns, new server signatures get folded in over time, so an IP that was clean last month can be listed today.

The smaller tells that finish the job

  • Open proxy ports & server fingerprints — common proxy/VPN ports and TLS signatures that no home connection exposes.
  • Geo / timezone mismatch — an IP in one country while your browser's timezone, language and other signals say another.
  • Reverse DNS — hostnames that read like hosting infrastructure rather than a consumer ISP.
  • Behaviour on top — once the IP looks suspicious, request patterns and fingerprints do the rest (the full stack is in how websites detect proxies and bots).

Why datacenter gets caught and residential doesn't

Put it together and the split is obvious. A datacenter IP is on a hosting ASN and already sits in every proxy database — two instant flags. A real residential IP is on a consumer ASN and isn't listed as a proxy, so there's nothing for the first line of detection to catch. That's the whole reason serious work runs on clean residential pools instead of cheap datacenter IPs.

You can see roughly what these systems see for any address with our free IP reputation checker — and note that even a genuine home IP can be flagged, which is its own story: can a residential IP have a bad reputation?

Proxysterr runs clean, ethically-sourced residential and mobile pools — rotating or sticky, from $1/GB, crypto, no KYC — so your traffic starts from IPs that pass the first check instead of failing it.