Guide

A Website Says VPN or Proxy Detected: Why It Happens and How to Read Clean

A site says VPN or proxy detected when your exit is on a known list, sits in a hosting range, or leaks a header. The fixes, with or without a proxy in play.

HProxy Team··Updated August 28, 2026·10 min read
HProxy.Guide

Skip the dead lists.

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump.

Open the free proxy list

The message is blunt and usually final: VPN or proxy detected, and the page refuses to continue. What the site is reporting is a classification rather than an accusation. A fraud or anti-bot service looked up your exit address, matched it against lists of known VPN and proxy endpoints, and returned a verdict before you touched anything on the page. We run a proxy network and FFraud, an IP-intelligence engine that produces exactly this kind of classification, so we can walk you through both sides of the counter: what makes an address read as a VPN or proxy, and what it takes to read as an ordinary connection.

Two very different people search this message. One is not using a proxy at all and has no idea why a streaming service or a shop suddenly treats them like one. The other runs a proxy on purpose and needs it to stop being seen. Both get their own fix section below, because the levers are different.

Why a website says you are using a VPN or proxy

Your exit address carries a signal that services look up in real time. Three signals dominate the verdict: the address appears on a published list of VPN or proxy endpoints, it belongs to a hosting or datacenter network that no ordinary person browses from, or the request leaks a proxy header that announces the hop. Any single one is enough for a site that buys this classification to refuse the connection. The verdict is a property of the address, which is why it arrives before the site has watched a single thing you do.

The verdict fires before the page loads
  1. Your request

    arrives with an exit IP

  2. IP lookup

    known-exit lists, ASN class

  3. Request read

    headers, ports, leaks

  4. Verdict

    pass, challenge, or refuse

Source: How commercial fraud and anti-bot services sequence the check

The five signals, and the lever each one gives you

The classification is built from a few readings. None of them is mysterious, and each one is something you can measure yourself before a site does.

It is on a known-exit list

Fraud-intelligence vendors such as DataDome, IPQualityScore, and MaxMind keep lists of addresses that operate as VPN or proxy endpoints, and sites query them on every request. A commercial VPN's exit ranges are shared by many thousands of users and become known quickly, so they reach these lists fast, often within days of going live. The wider detection stack behind this is walked in how websites detect proxies.

It belongs to a hosting network

Every address maps to an ASN, the public identifier of the network that owns it, and a hosting or datacenter ASN is itself the signal, because homes do not sit in server ranges. This is the input a datacenter proxy can never change, and the reason such an address shows up with a high fraud score even on the day it is born.

The request announces the hop

Some proxies attach headers (Via, X-Forwarded-For, Forwarded) or answer on a default proxy port, which advertises the extra hop directly, no list lookup required. The taxonomy of how loudly a proxy announces itself is its anonymity level, covered in transparent vs anonymous vs elite proxies. One request shows you exactly what a site receives:

# What the site sees: your exit address and any proxy header in the request
curl -x http://203.0.113.10:8080 -s https://httpbin.org/headers

A Via or X-Forwarded-For line in that output is a leak you can close at the client, and it will flag you no matter how clean the address is.

The browser leaks a second location

WebRTC can hand a site your real address through a STUN request even while every page load goes through the proxy, and a DNS resolver outside the tunnel tells the same story. The site now sees two locations at once and flags the mismatch. This is a client problem, not an address problem, which is why it survives every proxy change until you close it in the browser itself.

Too many identities from one address

An address that many unrelated accounts sign in from looks like shared or automated infrastructure, and shared infrastructure reads as a proxy even without a list entry against it. This one builds over time, which means an exit that passed on Monday can fail on Friday because of what other traffic did in between.

The signal a site readsWhat raises the VPN-or-proxy verdict
Known-exit listYour address is a published VPN or proxy endpoint
Hosting network (ASN)Your address sits in a datacenter range, not a consumer ISP
Proxy headers or portsThe request advertises a hop, via headers or a default proxy port
WebRTC or DNS leakThe client exposes a second, real location the exit does not match
Many accounts, one IPThe address looks like shared or automated infrastructure

Where the message shows up, and what each site is really checking

The wording changes from site to site, but the machinery behind it is the same classification with different thresholds.

Streaming services

Netflix shows "You seem to be using an unblocker or proxy" and pauses playback, and Hulu and Prime Video have their own versions of the same wall. Streaming services license content per country, so they buy the classification specifically to keep exits that hide the viewer's country out, and they run some of the strictest list matching there is. Datacenter VPN ranges are their easiest catch. What that means for proxy choice on these platforms is covered in proxies for Hulu, and the same logic holds across the category.

Shops, ticketing, and sneaker sites

Retail platforms fight automated buyers, so their thresholds are tuned for volume patterns: one address touching many carts, sessions that move faster than a human, headless browsers with mismatched fingerprints. The VPN-or-proxy message here is often the polite front of a bot verdict. The address class still decides the first gate, but these sites weigh the behavior readings more heavily than a streaming service does.

Banks and payment apps

Banks flag proxy exits because criminals hide behind them, and a login from a datacenter range on an account that normally connects from one city is exactly the pattern fraud teams alarm on. The honest advice is the boring one: do not put a proxy or VPN in front of your bank. The likely outcome is not access, it is a frozen account and a phone call, and no address quality changes that calculus.

Games and app stores

Game platforms mostly flag proxies around account creation, region switching, and purchases rather than play, and a flagged address at signup can shadow the account afterwards. The free-tier version of this problem, and why it usually ends in bans, is measured in free proxies for Roblox, and the pattern generalizes across launchers.

The fix when you are not using any proxy at all

The message without a proxy in play means something in your path reads as one. This list clears the overwhelming majority of those cases.

Clear a false VPN-or-proxy verdict on a normal connection

  1. 1

    Turn off software that proxies your traffic

    Antivirus web protection, some ad blockers, and privacy browsers route traffic through a local proxy, and sites read it. Turn the web-shield feature off, reload, and test again.

  2. 2

    Check the system proxy setting is actually off

    A closed VPN app can leave the system proxy switched on, so every browser still routes through a dead endpoint. Where that switch lives on every platform is in our guide to turning proxy settings off.

  3. 3

    Get a fresh address from your ISP

    Restart the router; most consumer connections pick up a different address on reconnect. If the message follows you across addresses, the whole range may be listed and it is worth telling your ISP.

  4. 4

    Test on mobile data

    If the site works over mobile data, the verdict is about your home or office address, not your account. Some carriers put thousands of customers behind one shared address, which occasionally lands on a flagged list through no fault of yours.

The fix when you run a proxy on purpose

Reading clean means removing each signal in the order of how heavily it counts. The address class dominates, so start there.

Read the exit before you trust it

Run the exit through our proxy checker to see the ASN, the network class, and the country, then put the same address through FFraud to see the fraud score and whether it is already classified as a VPN or proxy endpoint. A high score before you send any real traffic means the address arrived dirty, and no amount of careful use will un-list it. Finish with the curl call above to confirm the request carries no Via or X-Forwarded-For line.

Move the exit to a consumer ISP

The network class is the input that dominates the verdict, and a residential address satisfies it by design: it belongs to a real home ISP, so the ASN reads right and the address is not born on a datacenter list. Our residential proxies route through real home connections and start at $0.44/GB pay-as-you-go.

What the classifier reads on each exit class

FeatureDatacenter VPN exitResidential exit
ASN classhosting rangeconsumer ISP
On known-exit listsusually, and fastnot when the pool is maintained
Shared with strangersthousands per exitdepends on the pool
Survives streaming checksrarelyusually
Costflat subscriptionper GB

The residential exit removes the two signals that fire first, the hosting ASN and the list entry. It does not remove fingerprint or behavior checks, which belong to the client.

Signal weighting as fraud-intelligence vendors document it; see sources below

A residential label is not proof

A specific residential address can still be flagged if a previous user burned it, and classification is probabilistic either way. Read the exit in the checker and the fraud lookup before you rely on it: a clean exit is a snapshot you measure, not a property you inherit with the label.

That snapshot logic, and why yesterday's clean reading does not carry, is its own subject in what is a clean IP.

Close the client-side leaks

Use a proxy that does not add Via or X-Forwarded-For, and turn off WebRTC and DNS leakage in the browser so no second location contradicts the exit. Set the browser timezone to match the exit country, because a Berlin clock on a Dallas address is a mismatch no list can cause and no list entry can excuse.

Keep one identity per exit

Spreading unrelated accounts across a single exit is the pattern that reads as shared infrastructure even when the address itself is clean. For logins, hold one address per identity with a sticky session rather than rotating mid-account; the mechanics of that choice are in sticky vs rotating sessions. A VPN-or-proxy verdict is one specific way an address gets refused, and the broader set of refusal reasons lives in why is my IP blocked.

What reading clean does not buy you

A clean residential exit clears the classification that stops most VPN and proxy traffic, the address-level check, but detection does not end at the address. Sites also read your TLS fingerprint, your header order, your timezone measured against your IP's country, and your behavior across the session, so a clean address behind a headless client with a mismatched fingerprint still gets flagged, just one gate later. No address makes a browser that reports the wrong timezone look consistent with its exit. A believable exit removes the reason most of these verdicts fire, and a believable client removes the rest. Anyone selling an address that is never detected is selling the list entry, not the result.

Sources

Frequently asked questions

Why does a website say VPN or proxy detected?
Because a fraud or anti-bot service looked up your exit address and classified it as a VPN or proxy endpoint. Three signals dominate that verdict: the address is on a published list of known VPN and proxy exits, it belongs to a hosting or datacenter network that ordinary people do not browse from, or the request leaks a proxy header. Any one of them is enough for a site that buys this classification to refuse you, and the check happens before the site has seen anything you do.
How do websites detect a VPN or proxy?
They combine several lookups. Vendors publish lists of addresses that operate as VPN or proxy exits and sites query them per request. The address maps to a network (an ASN), and a hosting network is itself a signal. The request can carry proxy headers such as Via or X-Forwarded-For, or answer on a default proxy port. The browser can leak a real location through WebRTC or DNS that does not match the exit. And one address that many unrelated accounts sign in from reads as shared infrastructure.
How do I stop the VPN detected message?
Present an exit that removes each signal. Use an address that belongs to a consumer ISP rather than a hosting range, that is not on a known-proxy list, and that does not add proxy headers to the request. Close WebRTC and DNS leaks in the browser so no second location shows. Read the exit in a proxy checker and a fraud lookup before you rely on it, because the reading a site takes is the one that decides whether you pass.
Why does the message appear when I am not using a VPN at all?
Because something in your path reads as one. Antivirus web protection and some ad blockers route traffic through a local proxy, a leftover VPN app can hold a system proxy setting after you close it, and some mobile and satellite carriers put thousands of customers behind one shared address that ends up on a flagged list. Turning off the software proxy, clearing the system proxy setting, or getting a fresh address from your ISP usually clears it.
Why is my VPN detected but my home connection is not?
Commercial VPN exits sit in datacenter ranges, and those ranges are widely shared and quickly added to published VPN endpoint lists. Your home connection is neither a hosting range nor a listed exit, so it reads as an ordinary person. That difference is exactly what these detection services are built to measure, which is why a datacenter VPN is easy to flag while a real consumer ISP address is not.
Does a residential proxy stop the proxy-detected message?
It clears the address-level check, because a residential exit belongs to a real consumer ISP and is not on a datacenter or known-proxy list when the pool is maintained. It does not clear fingerprint or behavior checks, which read your TLS handshake, your headers, and your timezone against your IP's country. A specific residential address can also be flagged if a previous user abused it, so the exit still has to be checked rather than trusted.
What is a proxy header leak?
It is a header the proxy adds to your request that announces the extra hop, most often Via, X-Forwarded-For, or Forwarded, or the fact that the exit answers on a default proxy port. A site that reads one of those knows a proxy is in the path without any list lookup at all. A proxy that does not add these headers avoids the giveaway, and you can confirm what your request carries with a single curl call.
Is a VPN-or-proxy verdict ever wrong?
Sometimes. Classification is probabilistic, and a clean address can be misread if it recently changed hands or shares a range with flagged neighbors, while a flagged address occasionally slips through. That is why reading the exit yourself matters more than trusting a label: a fraud lookup shows you the score and the classification a site will act on before you commit real work to the address.

Get proxies that are alive right now

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump. When the location has to survive a real check, the paid network holds up.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup