Network Intelligence

Detect any level of anonymity with IP intelligence

Catch every VPN, proxy, and masked connection in your traffic, with ready-made risk signals and 99.9% risk signal detection accuracy

ShieldLabs Network Intelligence resolves a connection through IP reputation, connection fingerprint, and an active real-IP check into a single proxy signal

Prevent fraud at the source

Cut the abuse that rides in on masked connections

Stop blocking real customers

Tell genuine privacy-tool users apart from fraudulent traffic

No clean IP slips past

Catch the masked connections a static blocklist waves straight through

Cut your data costs

Skip the IP-data stack you'd otherwise buy and maintain yourself

Spot every kind of masking

Read across every network layer, on every visit, so nothing masked slips through

Accurate detection

Anonymous proxy detection plus VPN, Tor, Privacy Relay, datacenter, and IP reputation, at 99.9% risk signal detection accuracy

Detection of any anonymity

The inconsistencies a mask leaves across the IP, the network, the device, the OS, and the browser

Real IP behind the mask

The true connection that anonymized traffic is hiding

True location

Where a visitor really is, not where a mask says, with location spoofing caught

More than just an IP lookup

Accurate Identification

Identify returning visitors and users across sessions, cleared cookies, incognito mode, and rotated IP

Accurate Identification

Risk Signals

Detection of VPN, proxy, Tor, anti-detect browser, IP reputation and other risk signals on every visit, with 99.9% risk signal detection accuracy

Risk Signals

Risk Score

A ready-to-use score reflecting the risk of each visit, with the weight of every signal behind it

Risk Score

High-Risk Events

Direct detection of Multi-accounting, Account sharing, Impossible travel, and Account takeover, each with Medium or High confidence

High-Risk Events

Real-Time Analytics

See how much of your traffic is masked, with an overall quality score and a breakdown of the sources sending your visits

Real-Time Analytics

Catch the fraud hiding in every connection

Proxy and VPN-masked fraud

Flag checkout traffic routed through a proxy or VPN, even when the IP looks clean

Account takeover from a new network

Surface logins arriving on a masked or out-of-pattern connection

Residential-proxy multi-accounting

Expose repeat signups hiding behind rotating residential proxies

Location spoofing in payments

Catch the IP and timezone mismatch behind a faked location

Start detecting any level of masking in 5 minutes

Easily integrate into any signup, login, or checkout flow

  1. 1

    Create your account

    Get 5,000 free identifications

  2. 2

    Install the snippet

    It identifies every visitor and returns their risk signals and a risk score

  3. 3

    Check your traffic quality

    See how much of your traffic is masked, with an overall traffic score

  4. 4

    Use the API and Webhooks

    Act on the risk score and risk signals in your backend to stop fraud and abuse

api.shieldlabs.ai/v1/visits/latest
{
  "request_id": "0c284695-cf0b-4755-8beb-0a2e9536595e",
  "visitor_id": "aa8c616a-8a25-4a5e-bee2-a9a08e5128a4",
  "device_id": "6a45967d-1371-9652-ba99-b01ea3992208",
  "public_ip": { "ip": "62.197.149.124", "country": "United States" },
  "local_ip": { "ip": "45.83.91.7", "country": "United States" },
  "connection_type": "vpn",
  "os": "Windows",
  "browser": "Chrome",
  "device_type": "desktop",
  "risk_score": 35,
  "signals": [
    { "name": "vpn", "weight": 15 },
    { "name": "datacenter_ip", "weight": 10 },
    { "name": "proxy", "weight": 10 }
  ]
}

See the real connection behind every visit

Get ready-made risk signals and the real IP behind a mask running on your site in 5 minutes

Frequently asked questions

Network Intelligence is the connection-side capability that combines IP intelligence, the connection fingerprint, and the real IP behind a mask, returning risk signals like VPN, proxy, Tor, Privacy Relay, and datacenter. Device Intelligence is the device-side capability that builds a persistent identifier from the hardware, browser, and operating system. ShieldLabs runs them as a pair and returns both the identifiers and the network signals in one API response on the first visit, where a disagreement between the device and the connection is itself one of the strongest evasion signals.

ShieldLabs detects a proxy or VPN by reading several independent layers of the connection and returning a named risk signal instead of a single yes-or-no flag: the IP is checked against live reputation databases, inconsistencies are caught between the device, the OS, and the browser, and an active check looks for the real IP behind the mask. ShieldLabs flags a connection as masked when those checks agree, which produces 99.9% risk signal detection accuracy with a low false-positive rate, and returns the risk signal and a 0 to 100 risk score in one response.

In many cases, yes. Beyond the IP-reputation and connection-fingerprint layers, an active connection check reveals the originating IP behind an anonymizing connection. ShieldLabs treats the real IP as direct evidence of a mask when it surfaces, and when the real IP cannot be reached, that silence is itself a signal that raises the score rather than passing quietly.

Residential proxies are the hardest case, and ShieldLabs does not claim they are trivial, which is exactly why no single layer is trusted on its own. A pure IP-database lookup misses residential and freshly rotated IPs that look clean, so the passive connection fingerprint and the active real-IP check catch what a reputation list alone cannot. ShieldLabs reports 99.9% risk signal detection accuracy, not 100%, includes residential-proxy detection on self-serve plans, and always shows which network layers fired so a threshold can be tuned.

Yes. Proxy server detection reports the connection type instead of collapsing it into one flat flag, so ShieldLabs flags a datacenter proxy directly because the IP belongs to a known hosting provider, while a residential proxy routes through a real consumer IP that looks clean to a blocklist. ShieldLabs identifies the residential case through the connection fingerprint and the active real-IP check rather than a reputation lookup, so a datacenter proxy at checkout can be treated differently from a residential proxy on a logged-in session.

The Network Intelligence API covers VPN detection, proxy detection, Tor detection, datacenter, and Privacy Relay, returning a named risk signal for every connection plus a network fingerprinting result that reads the network-side operating system. The same call doubles as an IP geolocation API and an IP reputation API, so ShieldLabs returns location, reputation, and the masking verdict in one REST response with a 0 to 100 risk score instead of stitching together several vendors, the same depth that powers proxy and VPN detection.

No. ShieldLabs identifies anonymized connections and helps block fraudulent and abusive traffic without blocking legitimate VPN users: it returns a VPN, proxy, Tor, or datacenter risk signal plus a risk score with Details, and you choose the action for each case. A logged-in customer on a corporate VPN can be allowed while a fresh signup on a datacenter proxy is flagged. ShieldLabs bases the VPN signal on more than a single blocklist, and reports Privacy Relay separately, so legitimate VPN and privacy-conscious users are far less likely to be mislabeled.

A blocklist or GeoIP database is a single point of truth that goes stale and produces false positives, so ShieldLabs treats it as one input among several, alongside a passive connection fingerprint and an active real-IP check. The VPN signal fires when those checks agree, which produces 99.9% risk signal detection accuracy with a low false-positive rate. ShieldLabs hands back every signal with explainable Details showing why it fired, rather than a feed the team has to operationalize and a black-box flag it has to trust.