Is a reverse proxy classified as anonymizing?
Not automatically. Spur distinguishes anonymizing proxies and tunnels from non-anonymizing ones. When Spur detects a tunnel or proxy, the anonymous flag indicates which: false for corporate or ZTNA infrastructure attributed as a tunnel but not anonymizing, and true for an anonymizing proxy service. Methodology can vary slightly by product — contact support if you need product-specific detail.
Similar questions
How does Spur detect VPNs, residential proxies, and ISP proxies?
Spur uses a combination of network intelligence, infrastructure analysis, behavioral signals, routing characteristics, historical observations, and proprietary research to identify and classify IP addresses. Multiple signals are evaluated together to determine the likelihood that an IP belongs to a VPN, residential proxy network, ISP proxy service, hosting provider, or other category.
What should I do when I detect a VPN or proxy?
Detection alone should not automatically trigger a block. VPNs and proxies are used by both legitimate users and attackers. Most organizations incorporate VPN and proxy signals into broader risk-scoring or adaptive decisioning workflows that consider account history, geography, transaction context, and behavioral indicators.
Why might a residential IP be classified as a proxy?
Some residential IPs participate in proxy-sharing networks, malware-based proxy networks, commercial residential proxy services, or other infrastructure that causes them to exhibit proxy-like behavior. Spur evaluates multiple indicators before making classifications.
Why isn't traditional IP geolocation enough to enforce geographic restrictions?
Traditional geolocation only identifies where an IP address appears to be located. It does not reveal whether traffic is being routed through a VPN, residential proxy, mobile proxy, or other anonymization service. As a result, users can appear to originate from approved locations while actually operating elsewhere.
How do attackers use VPNs and residential proxies in account takeover attacks?
Attackers use VPNs and residential proxy networks to hide their true location, rotate IP addresses, and distribute login attempts across many seemingly legitimate users. This enables credential stuffing and account takeover campaigns to evade rate limits, IP reputation systems, and geographic controls. Spur IP intelligence helps identify these anonymization technologies and provides additional context that can be incorporated into authentication decisions.