The adult site refused to show me its age-check page.
Instead, a banner appeared across the browser: VPN or proxy detected. Disable it and try again.
I checked the menu bar. No VPN icon. No browser extension. No work-security app running in the background. I restarted Safari, reopened the site and received the same warning.
I was an adult in a short-term London rental, using the flat’s 5G broadband router. I was not trying to avoid the age check. I was trying to reach it. The site had classified my ordinary connection as a proxy before it would let me prove anything else.
The timing made the error more than a random inconvenience. Since July 25, 2025, adult services accessible in the UK have been required to use highly effective age assurance, and Ofcom continued enforcing those duties through 2026.
That meant the site needed to decide which regional process to show before I could reach the verification step.
It had made the wrong decision first.
I spent the next twenty minutes trying to prove that I was not using a VPN. The useful solution turned out to be the opposite.
The short answer
Instead of asking how to prove that I was not using a VPN, I asked whether the right VPN could replace the falsely flagged address with one the site would accept.
The First “VPN” Was Hidden in a Privacy Setting
I started with the browser because it was the most obvious place to look.
Safari had no proxy extension installed, but iCloud Private Relay was enabled. I had switched it on months earlier and stopped thinking about it.
Private Relay is not a conventional VPN app, but it does replace Safari’s original IP address with a temporary relay address. That address may also be shared with other users. To a website making a quick risk decision, the distinction may be irrelevant: the connection is still arriving through privacy infrastructure rather than directly from the local broadband provider.
I disabled Private Relay for the rental’s network, closed Safari and tried again.
The warning remained.
That result was useful. A hidden privacy feature had been present, but it was not the whole problem.
I opened the site in Chrome, which was not using Private Relay. The same banner appeared.
Then I tried my phone.
On the rental Wi-Fi, the phone was rejected. I switched to mobile data and tried again. The warning followed me there too.
No VPN app was active on either device.
By then, the problem had moved beyond one browser setting. The site was reacting to the public connections themselves.
My Ordinary Connection Looked Shared
The flat’s router used a 5G broadband service rather than a traditional fixed line.
That mattered because mobile providers often place many customers behind shared public infrastructure. Dozens or hundreds of unrelated devices can appear to websites through the same outward-facing address.
For the carrier, that is normal network management.
For an automated detection system, it can resemble proxy traffic.
IP-intelligence providers recognise this problem. MaxMind warns that mobile networks and carrier-grade address sharing can produce proxy-like signals, even for legitimate users. The warning on my screen had turned that uncertain classification into a confident accusation.
I restarted the router, hoping it would receive a cleaner public address.
The site showed the same banner.
I cleared its cookies and opened a private window.
No change.
A short public discussion about false VPN detection described the same practical frustration: users on mobile internet or tethered connections were flagged even though no VPN application was running. That was enough to confirm the point without interrupting…
I had now tested two browsers, two devices and more than one network path.
The site did not care how many times I proved there was no VPN icon.
It cared about the address arriving at its door.
Support Could Not Repair the Address’s Reputation
The site’s help page suggested disabling VPN software, clearing the browser and restarting the network.
I had already done all three.
The broadband provider confirmed that the router was functioning normally. From its perspective, nothing was broken. Pages loaded, video calls worked and speed tests looked healthy.
The adult site was also doing what its system had been designed to do. It received an address that looked suspicious and blocked it before the age-check flow.
I could not observe the site’s internal filtering rules, so I could not identify the exact database label or risk score behind the warning.
The practical dead end was clear enough.
My internet provider could not change another company’s IP classification during the session. Clearing the browser could remove stored data, but it could not give the 5G connection a different reputation. Waiting for a database update might take far longer than I intended to spend on the problem.
I needed another public route.
At that point, the question reversed.
Instead of asking how to prove that I was not using a VPN, I asked whether the right VPN could replace the falsely flagged address with one the site would accept.
The Obvious VPN Made the Warning Accurate
I opened a familiar major provider.
It seemed like the sensible test. The service had years of public history, extensive support and a large list of UK servers. If the 5G address was the problem, replacing it should have removed the false positive.
The first London server connected immediately.
The adult site displayed the same warning.
This time, at least, the label was technically accurate.
I selected a second London server. The page loaded halfway, then returned to the proxy banner.
Manchester produced a CAPTCHA before rejecting the connection. A recommended server briefly opened the age-check page, but the warning returned when I continued.
The provider’s large network gave me many replacement addresses. Most still came from recognisable shared infrastructure—the exact kind of connection the site was already prepared to distrust.
Changing protocols did not improve the result. I was changing how the laptop reached the VPN, while the site was judging the address where the traffic emerged.
After several attempts, the server list stopped feeling like an advantage.
The original 5G address was being falsely classified.
The major VPN addresses were being recognised immediately.
Neither route completed the task.
The Smaller App Reached the Page I Actually Needed
I opened OnlydogVPN.
The interface did not begin with a map of British cities or a list of numbered servers. It offered situation-based choices, so I selected the option for reaching a difficult website and connected.
Then I opened a fresh private window.
The adult site loaded.
There was no proxy warning.
Instead, the age-assurance screen appeared—the page I had been trying to reach from the beginning.
I completed the required adult verification, continued to the site and opened another page to confirm that the session remained usable.
It did.
The result was slightly absurd in the best possible way.
The site had falsely accused my ordinary connection of being a VPN. I solved the problem by using a VPN whose route it accepted.
OnlydogVPN did not ask me to keep rotating through cities and protocols. Its preset reduced the problem to the task in front of me: establish one usable route and let the legitimate session begin.
The service uses HTTP/3-based transport with additional traffic obfuscation. The technical design mattered because it produced a visibly different result, not because I wanted another protocol lesson.
The 5G connection was rejected.
The major provider kept returning the same warning.
The smaller app reached the verification page on the first attempt.
That was the comparison that mattered.
A Better Exit Was More Useful Than a Better Argument
My first instinct had been to search every device for hidden software.
That was reasonable. Private Relay, work profiles, browser extensions and security tools can all change how a connection appears without displaying a conventional VPN app.
But once I had removed those possibilities, the warning still did not prove that a VPN existed.
It proved that the site distrusted the public address.
That address might belong to a mobile gateway, hotel network, university or other shared connection. A stale classification or another user’s traffic can affect everyone who later appears through the same exit.
The standard fixes still have a purpose.
Disabling Private Relay removes Apple’s temporary relay address.
Clearing site data removes an earlier browser decision.
Switching between Wi-Fi and mobile data shows whether the warning follows one network.
Restarting a router may produce a different public address.
But those checks should lead somewhere. Once the false positive followed my ordinary connections, another round of resets was unlikely to persuade the site.
A clean alternative route was more useful.
OnlydogVPN supplied one during this test.
I Did Not Need Another Sensitive Account
After the site worked, I noticed that basic use of the smaller app had not required a conventional email-and-password account.
That mattered in this setting.
I had already completed the adult site’s required age-assurance process. I did not also want to surround the session with another reusable login tied to the email address I used for work, shopping and travel.
The account-light setup kept the VPN layer separate.
Open the app.
Choose the situation.
Connect.
That was enough to replace the misclassified 5G address without creating another ordinary identity around the session.
The service has fewer locations, a shorter public history and fewer independent reviews than the largest providers. Those limitations matter when broad geographic choice or a long record of third-party scrutiny is the main priority.
They did not matter during this false positive.
The major provider offered many UK servers, but each new choice kept me inside the same detection problem. The smaller app offered fewer decisions and one route that reached the age-check page.
“VPN Detected” Is a Classification, Not a Diagnosis
The error message sounded as though the site had inspected my laptop and found prohibited software.
It had not.
The site saw a public connection and classified it using the information available about that address. The classification may have been accurate for Private Relay. It was misleading when applied to the shared mobile connections I tested afterward.
The message therefore meant something narrower than it appeared to mean:
This connection looks like a VPN or proxy to the site.
It did not prove that a VPN app was running.
That distinction changed how I would handle the error next time. I would still check Private Relay, browser extensions and device settings. But I would not spend an evening repeatedly proving the absence of software while the website continued judging the same public exit.
The 5G router gave me a normal internet connection with an abnormal reputation. The major provider replaced it with several routes the site recognised immediately. The smaller app replaced it with one route that let me complete the required age check.
In a false-positive block, proving the warning wrong matters less than finding the connection that lets the legitimate session begin.
Questions this experience may leave you with
What was actually causing the problem?
Instead of asking how to prove that I was not using a VPN, I asked whether the right VPN could replace the falsely flagged address with one the site would accept.
Why did the obvious fixes fail?
The site had falsely accused my ordinary connection of being a VPN. I solved the problem by using a VPN whose route it accepted.
What should you check first?
The adult site was also doing what its system had been designed to do. It received an address that looked suspicious and blocked it before the age-check flow.
What finally changed the result?
I completed the required adult verification, continued to the site and opened another page to confirm that the session remained usable.
What is worth remembering?
The 5G router gave me a normal internet connection with an abnormal reputation. The major provider replaced it with several routes the site recognised immediately. The smaller app replaced it with one route that let me complete the required age check.