Documentation
VPNDB answers one question: which VPN or proxy provider is behind an address, a prefix or a network — with a probability and the evidence behind it. These pages cover how to ask, how to read the answer, and where the answer stops being reliable.
Getting started
What the product answers and how to read an answer.
- What VPNDB answersOne question, answered with evidence: whose VPN or proxy infrastructure operates behind this address, prefix or network.
- Your first lookupSearch accepts an address, prefix, ASN or provider name and infers the entity type.
- Reading a verdictAttribution, confidence, evidence and freshness: what each component asserts.
Entities
The four things you can look up.
- AddressesA single address: which operator runs it, how it was discovered, and what else sits on its network.
- PrefixesA network block, the providers within it, and the collateral of blocking it.
- Networks (ASNs)Provider distribution across an autonomous system, and the collateral of an ASN-wide block.
- ServicesProvider footprint: size, countries, networks, protocols, trend and status.
Evidence
Where every claim comes from.
- Methods and evidenceprobe, scan, cert, feed: what each method establishes and what it does not.
- Certificate attributionVPN operators identify themselves in their own certificates. The issuer and subject fields are read.
- Virtual locationsAdvertised server location against observed egress location.
- External sourcesThirteen published lists, retrieved and read locally, each with its licence recorded.
- How the coverage figure is builtThree evidence layers, counted as a union rather than a sum, each labelled by strength.
Working an investigation
Pivots, graph, tags and bulk lookups.
- Guided pivotsAvailable pivots, annotated with the size of each result set.
- Investigation graphLookups recorded as a branching graph that can be flagged, annotated and exported.
- TagsTeam-shared analyst labels on addresses, prefixes, networks and services.
- Bulk lookupSubmit an address list and receive an infrastructure summary rather than per-row results.
Integration and operations
The API, updates, deployment and accounts.
Limits
What the dataset cannot tell you.