Edge networks, so delivery is not mistaken for fraud.

Content delivery and edge ranges. Traffic arriving through an edge is infrastructure doing its job — it should not score like an anonymiser.

Schema at a glance.

See documentation →

The database's schema and metadata are documented carefully. Multiple formats are available, including CSVGZ and MMDB.

Sample rows for this build are not published yet. Ask us for a slice and we will send one from the current build.

ID
cdn_ip_v1
IP addresses
1,259
Refresh
Daily
CSVGZ
10 KB
MMDB
225 KB

Downloading it from code.

Database API reference →

One call gets you the current CDN IP build. Every official client wraps it three ways — straight to disk, a signed link you hand to your own runner, or bytes in memory — and each verifies the published checksum before it hands the build back.

download(path)
Streams the current build to disk and verifies the published checksum before it returns.
url(expires)
A time-limited signed link — hand it to your own downloader, a job runner or a CDN pull.
bytes()
The build in memory, for pipelines that never touch a filesystem.
build()
Build id, published time, row count, byte size and all four checksums.
format
csvgz, or mmdb where CDN IP publishes it.
since(build)
Poll the build id first and fetch only when it changed; an unchanged poll costs nothing.
from vpndetection import Client
client = Client(os.environ["VPNDETECTION_API_KEY"])
db = client.database("cdn_ip_v1", format="csvgz")
db.download("cdn_ip_v1.csv.gz") # to disk
url = db.url(expires=3600) # signed link
blob = db.bytes() # in memory
db.build().published # last build
download.pypip install vpndetection
Also available for C#, Ruby, Rust, Swift, Erlang, Zig and Perl. See all on GitHub →

Getting your hands on it.

Where CDN IP earns its place in a risk stack — and what each of these decisions needs from the data rather than from a score.

Stop scoring your own edge

If your traffic is fronted by a CDN, those addresses will appear constantly. Flagging them keeps them out of your risk signals.

Tell delivery from disguise

An edge network and a proxy network look similar from a single address. The distinction is the point of this dataset.

Attributed to the network

Provider names the edge operator so you can allow specific ones.

Licence the full database
Sales will quote on volume, term and whether you need redistribution rights.
Checksums published per file — md5, sha1, sha256 and sha512.
Every published build stays fetchable, so you can pin a version and roll forward when you choose.
Samples are cut from the current build, not a synthetic extract.

An official client for every major language.

All SDKs on GitHub →

Twelve official clients for the languages you ship in, each wrapping the database endpoints as well as the lookup — list what you are licensed for, poll a build, follow the download redirect. Install commands are in the docs.

On this page

How often does this dataset rebuild?

Every dataset publishes its own cadence and its last build date. The proxy datasets additionally carry a rolling 90-day observation window, so first seen and last seen are relative to that window.

00 · No key

Start without signing up.

Paste it into a terminal — no account needed. 1k daily allowance per user, answering ip and is_vpn.

curl "https://api.vpndetection.io/45.83.91.1"
{
"ip": "45.83.91.1",
"is_vpn": true
}
01 · Free key

Signup for 50k req/month.

No card, no sales call — the key is issued on signup.
Every request flags VPN IPs.
Upgrade only when you outgrow the allowance.