VPNDetectionVPNDetection

VPN IP Extended

VPN IP ranges with provider attribution, confidence and detection method.

Explore API
IDvpn_ip_extended_v1
Formatscsvgz, mmdb
Update FrequencyDaily
Last UpdatedSeptember 29th 2026 (yesterday)
Entries18,471,443
File Size (csvgz)129 MB
File Size (mmdb)170 MB

Overview

VPN IP ranges with provider attribution, confidence and detection method.

Formats

curl -L -o vpn_ip_extended_v1.csv.gz -X GET "https://api.vpndetection.io/api/v1/database/download?id=vpn_ip_extended_v1&format=csvgz&apikey=$APIKEY"
Schema
NameTypeDescription
start_ipipaddressStart IP of the IP range.
end_ipipaddressEnd IP of the IP range.
providerstringCommercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator.
methodstringHow this range was established. Values are listed below.
scan
We spoke the VPN protocol to the address ourselves and got a valid server response.
scrape
The operator published the address through its own API, client or configuration.
registry
Public registration or naming records attribute the address to the operator.
infer
The address was extrapolated from confirmed neighbours in the same block.
confidencestringConfidence of the correctness of this observation.
last_seendateLast time this observation was made.
Samples
start_ipend_ipprovidermethodconfidencelast_seen
152.171.7.236152.171.7.236draytekscanlow2026-08-28
76.53.164.276.53.164.2watchguardscanlow2026-09-22
186.132.148.30186.132.148.30draytekscanlow2026-08-13
172.238.64.96172.238.64.143psiphoninfermedium2026-09-29
2001:ac8:23:500:1012:5db5:7fb3:53a22001:ac8:23:500:1012:5db5:7fb3:53a2ovpnscanhigh2026-09-29
curl -L -o vpn_ip_extended_v1.mmdb -X GET "https://api.vpndetection.io/api/v1/database/download?id=vpn_ip_extended_v1&format=mmdb&apikey=$APIKEY"
Schema
NameTypeDescription
providerstringCommercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator.
methodstringHow this range was established. Values are listed below.
scan
We spoke the VPN protocol to the address ourselves and got a valid server response.
scrape
The operator published the address through its own API, client or configuration.
registry
Public registration or naming records attribute the address to the operator.
infer
The address was extrapolated from confirmed neighbours in the same block.
confidencestringConfidence of the correctness of this observation.
last_seendateLast time this observation was made.
Samples
providermethodconfidencelast_seen
draytekscanlow2026-08-28
watchguardscanlow2026-09-22
draytekscanlow2026-08-13
psiphoninfermedium2026-09-29
ovpnscanhigh2026-09-29

On this page