Skip to content
IP-060 IP Addresses & Networks

The IP belongs to a VPN provider—what do I do next?


title: "The IP belongs to a VPN provider—what do I do next?" card_id: "IP-060" status: "complete" source_document: "https://docs.google.com/document/d/10kKQJHP1mMTt4yHhh1iVhNRRn37Cf_pyVUiymLnWFeA/edit?usp=drivesdk"


The IP belongs to a VPN provider—what do I do next?

An IP address doesn't always lead to a home broadband or mobile subscriber.

Sometimes, it appears to belong to a commercial VPN provider.

If it does, the nature of the enquiry changes.

The online service has probably recorded the VPN’s exit IP address.

That’s the public address used by the VPN server when it connected to the service.

It isn’t necessarily the address normally used by the person’s home broadband or mobile connection.

First, confirm what you’ve actually identified.

An open-source check might identify the company controlling the network or data centre rather than the commercial VPN using it.

A database describing an address as a VPN is useful intelligence, but it isn’t necessarily proof by itself.

If you can identify the VPN service, the important question is whether its records can connect the outgoing activity to an incoming customer connection.

That’s different from asking an internet provider which subscriber was allocated an address.

Some VPN providers say they don’t retain connection logs.

If those records genuinely weren’t retained, the provider may be unable to identify which customer was using a particular exit IP address at a particular time.

But that doesn't necessarily mean the provider holds nothing.

It may still hold account information such as an email address, subscription details, payment-related records, customer-support communications or account-security information.

Some of that information may be held by another company, such as a payment processor, rather than by the VPN provider itself.

Account information can give you another line of enquiry.

But finding an account doesn't prove that the account used this particular VPN address at the relevant time.

That link depends on whether suitable connection records exist.

Before making any request, preserve the exact VPN exit IP address, the date and time, the time zone and any source port or session information recorded by the original service.

Then establish which VPN service was involved, which legal entity controls it, where that entity is based and what records it was capable of retaining at the relevant time.

Don't assume that a VPN address is automatically a dead end.

But don't assume that the provider can trace it back to a customer either.

A VPN places another service between the user and the platform that recorded the activity.

Your next job is to establish whether that service holds anything capable of reconnecting those two sides.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.