Can Sites Tell You’re Using a VPN?
Streaming services, banks and CAPTCHA walls look at two things: whether your address is on a list of datacenter and proxy addresses, and whether your browser contradicts it. This test looks at both, the way they do.
It cannot tell you what Netflix itself decides - its lists are private - but it shows the signals such services can rely on: the lists your address is on, and what your browser says that contradicts it.
How often VPN exits are on these lists
Our measurement stand connects to each provider every six hours and records how ip-api.com classifies the exit address - the same lookup this test uses on yours.
| Provider | Listed as datacenter | Listed as proxy | Runs |
|---|---|---|---|
| Mullvad (NL) | 100% | 77% | 118 |
| ProtonVPN (free servers, NL) | 100% | 100% | 134 |
One server location per provider, from one datacenter, so it shows how these exits are classified, not every server a provider runs. Whether a given streaming service blocks them is a separate question we have not measured yet. Method and full figures
How Sites Tell a VPN Apart
The address comes first. Commercial databases sort addresses into home broadband, mobile, business, datacenter and known proxy or VPN exits. A VPN server in a datacenter has an address on those lists - the table above shows how often our lab finds the exits it measures listed - and a service that blocks VPNs can do it without looking at anything else. That is why the “proxy detected” screen can appear however carefully the browser is set up.
Then the contradictions. A clean address can still be given away by the browser: a timezone in another country, WebRTC showing a second public address, or a network like Cloudflare placing you somewhere else. Fraud and anti-bot systems weigh these together; a single mismatch is one signal among several, but they add up.
What does not work the way people fear: browser language is weak, because browsers follow the system’s language and English is used far beyond English-speaking countries, and location needs your permission, so a site cannot read it behind your back.
If the Verdict Says “Visible”
| What gives you away | What changes it |
|---|---|
| Address on a datacenter or proxy list | Only a different exit: another server, or a provider’s dedicated or residential address option where it offers one. Browser settings cannot fix this. |
| WebRTC shows another address | Turn on your VPN app’s WebRTC protection, or disable WebRTC in the browser. Check it here. |
| Timezone in another country | Set the system timezone by hand to the exit country’s, or use a browser that reports a generic one. |
| Cloudflare sees another country | WARP or a proxy chain in the path can do this. Turn off whatever else is routing your traffic. |
Can Sites Tell I'm Using a VPN? - FAQ
What streaming services and other sites can see, and what this test does with your address.
Can Netflix tell I am using a VPN?
It can, from the address alone. Netflix and other streaming services block known VPN and datacenter addresses from lists, some bought and some of their own. This test shows whether your address is on the lists we can check (ip-api.com’s datacenter and proxy flags). If it is, a service that blocks VPNs can tell. If it is not, that is a good sign but not a guarantee: their own lists are private, and nobody outside can test against them.
Why does my VPN get the "proxy detected" error?
Because the exit address is listed as a datacenter or proxy. Our lab records how the measured providers’ exits are classified on every run; the table above has the figures. Changing your timezone or language does not help; only a different exit address does.
Does my browser language give me away?
Not much. Browsers follow the system’s language, English is used far beyond English-speaking countries, and many people read sites in a language that is not their country’s, so sites cannot lean on it. This test shows it, but it never decides the verdict.
Does a timezone mismatch matter?
It is one of the stronger browser signals. Every site can read your timezone with one line of JavaScript, and a timezone in another country than your address tells it the address is not where you are. Fraud and anti-bot systems weigh it; on its own it is one signal among several.
Can sites see my real location through GPS?
Only if you allow it. Browsers ask before a site can read your GPS or Wi-Fi position, so it is never a hidden signal. This test reads whether you have allowed this site, without asking for the permission itself.
What does this test send, and where?
Our server looks up your address with ip-api.com to get its country, timezone, network and the two list flags, and stores none of it; the answer is cached for 30 minutes under a hash that changes daily, without the address. Your browser asks Cloudflare (1.1.1.1) where it places you and makes one WebRTC request to Cloudflare’s STUN server. Nothing is saved unless you tick the share box after the test, and a shared result never contains your address.