Your IP and your timezone
Three things should agree: the address our server sees, the address your browser finds for itself, and the clock on your machine. When they do not, something is sitting between you and the internet.
Checking your connection
Resolving your address and gathering WebRTC candidates.
The address we see
The address your browser found
Clocks
Your machine
Where your IP lives
Look up any address
How this test works
The address we see
Every HTTP request carries a source address. If you browse through a VPN or an HTTP proxy, that is the proxy's address, not yours. We resolve it to a country, a network operator and a timezone, and check it against reputation data for known hosting ranges and anonymising exits.
The address your browser finds
WebRTC needs to know how a peer can reach you, so it asks a STUN server over UDP. That probe leaves your machine directly. An HTTP proxy never touches it, and a browser extension that only rewrites web requests cannot intercept it. If the address that comes back differs from the one on your HTTP request, your web traffic is being proxied and your real address just leaked.
Chrome and Edge hide your local network addresses behind random
.local names. That is a separate protection, and it does not cover the
public address discovered through STUN.
The clock
A proxy moves your apparent location but not your system clock. A visitor whose browser is on Indian Standard Time arriving from a Frankfurt datacenter is worth a second look. We also check that your browser's timezone is internally coherent: the zone name, the current offset and the daylight saving behaviour all come from the same system database in a genuine browser, so they cannot disagree with each other.
Using a VPN is not fraud. Plenty of people have good reasons to hide their location. These signals are useful because they add context, not because any one of them proves wrongdoing.