VPN Checker - Detect VPN & Proxy Connections

Find out whether a connection runs through a VPN, a proxy or the Tor network. Open the page and it tests your own connection straight away, so you can see whether your VPN is working. Enter any other IP address to check that instead.

VPN Check — 9.9.9.9

Infrastructure
Public DNS resolver, not an anonymising service

This address belongs to Quad9 DNS. It runs in a datacenter and answers DNS queries for the public, so it is not a residential connection and not an anonymising service.

IP Address
9.9.9.9
Provider Name
Quad9 DNS (AS19281 Quad9)
Service Type
Public DNS / infrastructure
Threat Level
Low
VPN Service
No
Proxy Server
No
Tor Exit Node
No
Hosting/Datacenter
Yes — Datacenter IP

Is my VPN working? A 3-step test

The check above reads the IP address your traffic arrives from. Run it twice, once without the VPN and once with it, and the comparison tells you whether the tunnel is carrying your traffic.

  1. Disconnect the VPN and note what you see. Write down the IP address, the provider name and the city on this page. That is your real connection, and it is what every website sees when the VPN is off.
  2. Connect the VPN, then reload this page. Wait until the VPN app says it is connected before you reload, or you will measure the old connection again.
  3. Compare the two results. A working VPN gives you a different IP address, a different provider name and usually a different city. The Service Type should read as a VPN, a proxy or a hosting network rather than a consumer ISP, because VPN servers live in datacenters.

Passing all three steps still leaves two ways to give yourself away. Your device can send DNS queries outside the tunnel, and your browser can reveal your real address through WebRTC. Finish the test with our DNS leak test and our WebRTC leak test.

Why the checker may say no VPN while you are connected

Seeing your own ISP here while the VPN app shows a green light usually means one of these:

  • Split tunnelling is on. This feature sends only chosen apps through the tunnel. If your browser is not on that list, your traffic reaches us directly and you see your real IP address.
  • You are testing from the wrong browser. A proxy extension protects only the browser it is installed in. Open this page in that browser, because every other app on the device still uses your ordinary connection.
  • The VPN uses residential addresses. Some providers route you through real home broadband lines. Those addresses belong to consumer ISPs, so detection databases have no reason to flag them.
  • The app quietly dropped. VPN clients reconnect after sleep, a network change or a dead server, and some show connected while the tunnel is down. Toggle it off and on, then reload.
  • The provider is small or new. Our data source lists known VPN and proxy ranges. A range added last week may not be in it yet, which is why a negative result means nothing was found rather than nothing is there.

Understanding This Tool

What It Does

Check whether an IP address is associated with a VPN, a proxy or a Tor exit node, and see which network it belongs to. The check reads live connection data for the address and sorts it into one of a few buckets: an anonymising service, a datacenter range, public DNS infrastructure, or an ordinary ISP connection.

Understanding the Results

  • Provider Name: The organisation that owns the address, with its autonomous system number
  • Service Type: VPN service, proxy service, Tor exit node, hosting or datacenter network, public DNS infrastructure, or consumer ISP
  • Threat Level: Low, Moderate, Elevated or High, derived from which anonymity signals came back positive
  • VPN, Proxy and Tor rows: Each signal reported individually, so you can see what drove the verdict
  • Hosting/Datacenter: Whether the address sits in a server range rather than a home or office connection
  • Detection Confidence: Shown only when at least one signal is positive. No badge means no signal fired, which is weaker evidence than a clean bill of health

Common Use Cases

  • Account Security: Look into a login from an address you do not recognise
  • Fraud Review: Add context to a transaction before you approve or hold it
  • Privacy Testing: Confirm your own VPN is carrying your traffic
  • Log Triage: Tell a datacenter crawler apart from a real visitor
  • Abuse Reports: Identify the network operator to contact about an address

Pro Tips & Best Practices

  • Absence Is Not Proof: "No signals found" means our data source has nothing on the address, not that the connection is definitely direct
  • Public Resolvers Look Like Datacenters: Addresses such as 8.8.8.8 and 1.1.1.1 sit in datacenter ranges but anonymise nothing, so they are labelled as infrastructure
  • Corporate Networks Get Flagged: Office egress proxies and cloud VPN gateways can register as proxy traffic
  • Ranges Move: Providers rotate address space, so re-check an address rather than trusting an old result
  • Do Not Block on One Signal: Plenty of people use a VPN for ordinary privacy reasons

Frequently Asked Questions

How does VPN detection work?
VPN detection analyzes IP characteristics including datacenter hosting, known VPN provider ranges, connection patterns, and proxy signatures to determine if an IP is likely using a VPN service with a confidence score.
Can all VPNs be detected?
Most commercial VPNs can be detected with high accuracy (90%+), but some residential proxies and advanced obfuscation techniques may evade detection. Detection accuracy varies by VPN provider.
What's the difference between VPN, proxy, and Tor?
VPNs encrypt all traffic and route through commercial servers. Proxies route specific traffic without encryption. Tor routes through multiple volunteer nodes for anonymity. Our tool detects all three types.
Why would I need to check if an IP is using a VPN?
Common uses include fraud prevention (detecting fake locations), content protection (enforcing geographic restrictions), account security (detecting suspicious access patterns), and compliance verification.
What does the confidence score mean?
The confidence score appears only when we detect a VPN, proxy or Tor association, and it reflects how strongly those signals fired. When no badge is shown, our data source has nothing on the address. That is weaker evidence than a clean bill of health, so treat it as "nothing known" rather than "definitely not a VPN".
Can VPN detection be wrong?
False positives can occur with datacenter-hosted services, corporate networks, or cloud providers that share IP characteristics with VPNs. Always consider the confidence score and context.
Last reviewed: Reviewed by the

How this tool works: This tool runs in your browser and on our server in real time. Depending on the tool, results are computed directly from the input you provide or retrieved from live, authoritative data sources at the moment you run a lookup. We do not sell your data, and your lookups are kept private — any history shown here is stored only on your device.