InternetDataInternetData

VPN IP Extended

VPN IP v1 with evidence data behind every range.

Explore API
IDvpn_ip_extended_v1
Formatscsvgz, mmdb
Update FrequencyDaily
Last UpdatedSeptember 30th 2026 (yesterday)
Entries18,456,899
File Size (csvgz)129 MB
File Size (mmdb)171 MB

Overview

Everything in VPN IP, plus a method column recording how each range was established. Use it when a single confidence grade is too coarse and you want to weight ranges by the kind of evidence behind them.

Formats

curl -L -o vpn_ip_extended_v1.csv.gz -X GET "https://internetdata.io/api/v2/database/download?id=vpn_ip_extended_v1&format=csvgz&apikey=$APIKEY"
Schema
NameTypeDescription
start_ipipaddressStart IP of the IP range.
end_ipipaddressEnd IP of the IP range.
providerstringCommercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator.
methodstringHow this range was established. Values are listed below.
scan
We spoke the VPN protocol to the address ourselves and got a valid server response.
scrape
The operator published the address through its own API, client or configuration.
registry
Public registration or naming records attribute the address to the operator.
infer
The address was extrapolated from confirmed neighbours in the same block.
confidencestringConfidence of the correctness of this observation.
last_seendateLast time this observation was made.
Samples
start_ipend_ipprovidermethodconfidencelast_seen
202.70.159.28202.70.159.28fastestvpninferlow2026-09-20
167.98.44.235167.98.44.235watchguardscanlow2026-09-23
134.236.40.156134.236.40.156watchguardscanlow2026-09-21
118.179.93.12118.179.93.12best_proxy_switcherinferhigh2026-09-05
86.84.199.16386.84.199.163draytekscanlow2026-09-27
curl -L -o vpn_ip_extended_v1.mmdb -X GET "https://internetdata.io/api/v2/database/download?id=vpn_ip_extended_v1&format=mmdb&apikey=$APIKEY"
Schema
NameTypeDescription
providerstringCommercial VPN provider's unique ID. Empty when the range is confirmed VPN infrastructure we have not yet attributed to a named operator.
methodstringHow this range was established. Values are listed below.
scan
We spoke the VPN protocol to the address ourselves and got a valid server response.
scrape
The operator published the address through its own API, client or configuration.
registry
Public registration or naming records attribute the address to the operator.
infer
The address was extrapolated from confirmed neighbours in the same block.
confidencestringConfidence of the correctness of this observation.
last_seendateLast time this observation was made.
Samples
providermethodconfidencelast_seen
fastestvpninferlow2026-09-20
watchguardscanlow2026-09-23
watchguardscanlow2026-09-21
best_proxy_switcherinferhigh2026-09-05
draytekscanlow2026-09-27

Method

method is a small, stable vocabulary. New methods are folded into an existing class, so you can switch on these values and stay correct as our coverage grows.

scan

We spoke the VPN's protocol ourselves and got a valid server response. This is a direct observation and comes with a guarantee that the IP is operating with VPN-like software as an entry and/or exit node.

Where provider is empty, the address is confirmed VPN infrastructure that we were unable to tie to a named provider at the current time. It may be attributed later, or it may be non-commercial, or simply a corporate VPN setup.

scrape

The provider published the address publicly or privately, either through its own API, client software, configuration, DNS, or website, and we were able to query it or reverse engineer it.

registry

Public registration and naming records attribute the range to the provider, including RIR WHOIS netname and organisation fields, reverse-DNS naming, and self-published geofeeds.

infer

The address sits inside a small prefix in which we independently confirmed a large threshold of VPN addresses. This extends coverage across the remainder of a block a provider is demonstrably operating from.

Confidence vs. Method

The same two methods may come with different confidence scores for the same provider, so the confidence score is still important to take into account. This is because some methods have a lot more reliability for a given provider's infrastructure than another's.

For example, infer may be almost always right in capturing the /24 CIDR a provider has leased and thus have confidence=high, while for another it is simply a guess due to a high threshold being reached and thus have confidence=low.

Similarly, the registry method for two providers where RDNS was used may give different confidence scores because one provider's RDNS is always up-to-date, forward-confirmed, and they generally correctly identify it with VPN infrastructure, whereas another's may be more out-of-date, not forward-confirmed, etc.

On this page