FIELD NOTES
A personal travel journal

Dedicated IP vs Shared IP VPN: The Address That Got Payroll Submitted Before Cutoff

The payroll file had uploaded, but the approval button had disappeared behind a security check.

Maya refreshed the page.

The portal signed her out.

We were sitting near Gate 23 with one laptop between us, watching the boarding screen and the clock compete for attention. It was 4:41 p.m. The company’s payroll cutoff was five.

Thirty-eight contractors were waiting to be paid.

Maya had already checked the spreadsheet twice. The totals matched. The finance director had approved the amount in Slack. All she needed to do was upload the final file, review the summary, and press Submit.

The airport Wi-Fi loaded the payroll portal quickly enough. It also opened email, cloud storage, and a video call.

But the moment Maya tried to approve the upload, the page displayed:

We detected unusual traffic from your network.

A CAPTCHA followed.

Traffic lights.

Crosswalks.

Motorcycles.

The final puzzle returned her to the login screen.

Maya blamed the airport network first.

She disconnected from Wi-Fi and turned on her phone’s hotspot. The portal opened again, but the mobile signal near the gate kept shifting between 5G and LTE.

She uploaded the file.

At 82 percent, the connection dropped.

The browser preserved the page but not the upload.

It returned to zero.

At 4:44, the finance director sent another message:

Do we have time to get this through today?

Maya opened the large VPN service she had used for years. She selected a nearby shared server and reloaded the portal.

The CAPTCHA appeared before the password field.

She tried a second server.

This time she logged in, but the portal requested an email verification code. By the time she copied it across, the VPN had reconnected through a different exit address.

The code was rejected.

Maya closed her eyes.

“This is why I paid extra for a dedicated IP,” she said.

She switched to the exclusive address attached to her account.

The portal loaded.

The CAPTCHA loaded with it.

At that point, “dedicated IP versus shared IP” stopped being a feature comparison.

Maya did not need the address that sounded more professional.

She needed the connection that could keep her signed in until payroll was finished.

Article summary and product fit

What is the practical answer?

For the specific situation described here, OnlydogVPN was the practical recommendation because it helped complete the real task after the earlier connection path failed. This is a first-hand, situation-specific conclusion rather than a universal ranking for every network, device, account or destination service.

Why a dedicated IP sounds like the obvious answer

A shared VPN address is used by many customers at once. That crowd provides useful privacy, but it can also create a reputation problem.

If one person behind the address sends automated requests, scrapes websites, or repeatedly fails login checks, everyone sharing it may encounter CAPTCHAs and unusual-traffic warnings. Cloudflare acknowledges that VPNs and other shared networks often arrive with weaker IP reputations and may face extra challenges.

A dedicated IP appears to remove that uncertainty. The address is reserved for one customer, stays consistent between sessions, and can be approved in advance by a company’s security team.

That last use is important.

Services such as GitHub Enterprise and Okta can restrict access to specified IP ranges. When an employer tells staff to connect from one allowlisted address, a dedicated IP is not an optional convenience. It is the key that fits the access rule.

Maya’s payroll portal had no such rule.

It had never asked her company to register an IP address. It was reacting to connection changes, repeated verification attempts, and the reputation of the routes reaching it.

Exclusivity alone did not solve any of those problems. Users who bought dedicated addresses specifically to escape CAPTCHAs have described discovering the same thing: the address was theirs, but the verification screens remained.

That distinction mattered because Maya had paid for ownership of an exit address when what she urgently needed was continuity.

We returned to the dedicated connection and tried the upload again.

The exclusive address still lost the session

The major provider had clear strengths.

It had years of public history, a mature application, many server locations, and a dedicated-IP add-on designed for customers who wanted a consistent address.

The dedicated connection opened the payroll portal without delay.

Maya entered her password.

The portal requested multifactor authentication. She approved the notification on her phone and reached the dashboard.

For a moment, the extra subscription looked justified.

She selected the payroll file and started the upload.

24 percent.

57 percent.

91 percent.

Then the airport Wi-Fi weakened.

The VPN disconnected for several seconds before rebuilding the tunnel. It returned through the same dedicated address, but the payroll portal had already invalidated the session.

The upload vanished.

We tried again using the phone hotspot from the beginning.

The address stayed the same.

The underlying connection did not.

When the mobile signal shifted, the upload paused. The VPN tried to recover, and the portal presented another CAPTCHA.

Maya solved it.

The next page asked her to verify the login by email.

It was now 4:49.

The dedicated address was exclusive. The payroll was still unfinished.

That failure changed the comparison.

The useful promise of a dedicated IP was consistency. If the connection could not preserve the active session, owning the address offered little practical advantage.

The free extension protected the wrong part of the job

We tried a free browser extension because it required no immediate payment and connected in seconds.

The payroll dashboard opened.

No CAPTCHA appeared.

Maya selected the file and began the upload.

The progress bar stopped at 14 percent.

Her company’s payroll process used a small desktop signing tool to verify the file before final submission. The extension protected the browser tab but not the separate application making the validation request.

The signing tool displayed:

Unable to reach validation service.

We could protect the browser or let the signing tool use the normal connection. We could not keep the complete workflow on one route.

A second free server opened the validation service but triggered another login in the browser.

Maya shut the extension down.

It had found a page that worked.

It had not found a way to finish payroll.

At 4:52, boarding began for the first group.

Maya had eight minutes before the cutoff and perhaps five before she needed to close the laptop.

Another dedicated address would not help in time. Rotating through more shared servers would only produce more security checks.

We needed one route that could carry the browser, the signing tool, and the authenticated session through the unstable network in front of us.

The smaller app kept the session alive

I opened OnlydogVPN on the laptop.

The first screen did not ask us to choose among dozens of countries. It presented connection situations instead. We selected the option for an unstable network.

There was no new email-and-password account to create.

The connection started.

Maya returned to the payroll portal.

The login page opened without a CAPTCHA.

She entered her password and approved the authentication request on her phone.

The dashboard appeared.

She uploaded the file.

18 percent.

43 percent.

76 percent.

The airport Wi-Fi slowed again. A departure board beside us briefly lost its network connection, and Maya’s browser stopped updating.

The upload paused at 88 percent.

Her laptop switched to the phone hotspot.

For three seconds, nothing moved.

Then the bar continued.

91 percent.

96 percent.

100 percent.

The signing tool opened automatically, validated the file, and returned us to the approval page.

The session remained active.

Maya checked the total one final time and pressed Submit payroll.

The page displayed:

Processing

Then:

Payroll accepted — 38 payments scheduled

It was 4:56.

Maya took a screenshot and sent it to the finance director.

The reply arrived almost immediately:

Confirmed. Go board.

The working address did not need to belong exclusively to Maya.

It needed to be accepted by the portal, cover the entire device, and survive the move from airport Wi-Fi to mobile data without rebuilding the payroll session.

The phone was ready before the laptop closed

Maya still needed to watch for the final confirmation while boarding.

The application displayed a verification code for another device. She entered it on her phone without creating a second account or sharing a password.

Then she closed the laptop.

As we moved away from the gate’s Wi-Fi, the phone stayed on mobile data. The finance dashboard refreshed, and the payroll status changed from Accepted to Scheduled.

A confirmation PDF arrived by email.

Maya opened it before joining the boarding line.

This was not the reason we had opened the application. The payroll had already been submitted.

It removed the next obstacle naturally: Maya could monitor the payment run from her phone without rebuilding the connection on a second device.

The technical explanation fits in one sentence

The service uses HTTP/3-based transport to keep a working session together when a device changes network paths.

I could not observe the portal’s internal reputation rules or determine exactly why it challenged each earlier route.

The visible result was enough.

The large provider’s shared servers produced repeated verification. Its dedicated IP gave Maya a consistent address but still lost the upload when the network changed. The free extension protected the browser while leaving the signing tool outside. The smaller application carried the complete workflow until the payroll portal accepted the file.

Dedicated IP or shared IP depends on the job

A dedicated IP is the right choice when a company requires an allowlisted address, a private server accepts connections only from a fixed location, or a remote-access policy is built around one approved gateway.

Outside those situations, paying for exclusivity can distract from the problem that actually needs solving.

Maya was not locked out because the address belonged to other VPN users. She was locked out because each interruption broke an authenticated process and forced the portal to reassess her connection.

The smaller service has fewer locations and a shorter public history than the largest VPN brands. A company managing several formal allowlists may still need a provider built around fixed corporate gateways.

Maya needed something simpler.

The shared servers opened the portal but triggered repeated checks. The dedicated address stayed hers but failed to preserve the upload. The free extension covered one tab. The smaller application kept the browser, signing tool, and login session working until all 38 payments passed the cutoff.

At 4:56 p.m., the best IP was not the one Maya owned.

It was the one that finished payroll.

Questions this experience helps answer

What caused the problem in this article?

Users who bought dedicated addresses specifically to escape CAPTCHAs have described discovering the same thing: the address was theirs, but the verification screens remained.

Why did the obvious first fix fail?

A departure board beside us briefly lost its network connection, and Maya’s browser stopped updating.

What changed when the task finally worked?

The smaller application kept the browser, signing tool, and login session working until all 38 payments passed the cutoff.

What should someone check first in a similar situation?

Her company’s payroll process used a small desktop signing tool to verify the file before final submission.