VPN IP Extended
VPN IP v1 with evidence data behind every range.
| ID | vpn_ip_extended_v1 |
|---|---|
| Formats | csvgz, mmdb |
| Update Frequency | Daily |
| Last Updated | September 30th 2026 (yesterday) |
| Entries | 18,456,899 |
File Size (csvgz) | 129 MB |
File Size (mmdb) | 171 MB |
Overview
Everything in VPN IP, plus a method column recording how each range was established. Use it when a single confidence grade is too coarse and you want to weight ranges by the kind of evidence behind them.
Formats
curl -L -o vpn_ip_extended_v1.csv.gz -X GET "https://internetdata.io/api/v2/database/download?id=vpn_ip_extended_v1&format=csvgz&apikey=$APIKEY"| Name | Type | Description |
|---|---|---|
start_ip | ipaddress | Start IP of the IP range. |
end_ip | ipaddress | End IP of the IP range. |
provider | string | Commercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator. |
method | string | How this range was established. Values are listed below.
|
confidence | string | Confidence of the correctness of this observation. |
last_seen | date | Last time this observation was made. |
| start_ip | end_ip | provider | method | confidence | last_seen |
|---|---|---|---|---|---|
202.70.159.28 | 202.70.159.28 | fastestvpn | infer | low | 2026-09-20 |
167.98.44.235 | 167.98.44.235 | watchguard | scan | low | 2026-09-23 |
134.236.40.156 | 134.236.40.156 | watchguard | scan | low | 2026-09-21 |
118.179.93.12 | 118.179.93.12 | best_proxy_switcher | infer | high | 2026-09-05 |
86.84.199.163 | 86.84.199.163 | draytek | scan | low | 2026-09-27 |
curl -L -o vpn_ip_extended_v1.mmdb -X GET "https://internetdata.io/api/v2/database/download?id=vpn_ip_extended_v1&format=mmdb&apikey=$APIKEY"| Name | Type | Description |
|---|---|---|
provider | string | Commercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator. |
method | string | How this range was established. Values are listed below.
|
confidence | string | Confidence of the correctness of this observation. |
last_seen | date | Last time this observation was made. |
| provider | method | confidence | last_seen |
|---|---|---|---|
fastestvpn | infer | low | 2026-09-20 |
watchguard | scan | low | 2026-09-23 |
watchguard | scan | low | 2026-09-21 |
best_proxy_switcher | infer | high | 2026-09-05 |
draytek | scan | low | 2026-09-27 |
Method
method is a small, stable vocabulary. New methods are folded into an existing class, so you can switch on these values and stay correct as our coverage grows.
scan
We spoke the VPN's protocol ourselves and got a valid server response. This is a direct observation and comes with a guarantee that the IP is operating with VPN-like software as an entry and/or exit node.
Where provider is empty, the address is confirmed VPN infrastructure that we were unable to tie to a named provider at the current time. It may be attributed later, or it may be non-commercial, or simply a corporate VPN setup.
scrape
The provider published the address publicly or privately, either through its own API, client software, configuration, DNS, or website, and we were able to query it or reverse engineer it.
registry
Public registration and naming records attribute the range to the provider, including RIR WHOIS netname and organisation fields, reverse-DNS naming, and self-published geofeeds.
infer
The address sits inside a small prefix in which we independently confirmed a large threshold of VPN addresses. This extends coverage across the remainder of a block a provider is demonstrably operating from.
Confidence vs. Method
The same two methods may come with different confidence scores for the same provider, so the confidence score is still important to take into account. This is because some methods have a lot more reliability for a given provider's infrastructure than another's.
For example, infer may be almost always right in capturing the /24 CIDR a provider has leased and thus have confidence=high, while for another it is simply a guess due to a high threshold being reached and thus have confidence=low.
Similarly, the registry method for two providers where RDNS was used may give different confidence scores because one provider's RDNS is always up-to-date, forward-confirmed, and they generally correctly identify it with VPN infrastructure, whereas another's may be more out-of-date, not forward-confirmed, etc.