FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

I Had Done Nothing Wrong—So Why Was My VPN IP Blacklisted?

The website accused my connection before it showed me the page.

Access denied. This IP address has been associated with suspicious activity.

I was at home in Melbourne, trying to open a video from a sexual-wellness course my partner and I had already paid for. We had a counselling appointment the next morning, and the video contained an exercise we were supposed to complete beforehand.

Australia’s new age restrictions had recently taken effect, so I connected through a major VPN rather than begin another identity check.

The app said I was in Auckland.

The course website said I was suspicious.

I assumed I had chosen a bad server. I switched to Los Angeles and refreshed.

The block returned.

Singapore produced a CAPTCHA. Sydney displayed the age-verification screen I had been trying to avoid. Another New Zealand server returned the original access-denied message.

I opened Google to search for the error.

Google asked me to prove I was human too.

By then, I was wondering whether something on my laptop had been compromised. I had not scraped a website, created fake accounts, sent spam, or run an automated tool.

I had watched half a relationship course and tried to open the next lesson.

Yet every page seemed to recognise the VPN address before it recognised me.

The short answer

Google explains that unusual-traffic warnings can appear when requests from a VPN network resemble automated activity. ( Google ) The person solving the CAPTCHA may have done nothing wrong. The activity that damaged the address may have come from someone else using the same exit earlier.

New VPN users were arriving through the same exits

The timing mattered.

Australia’s Age-Restricted Material Codes began applying across major parts of the online ecosystem on March 9, 2026. Pornography sites, social platforms carrying restricted content, app services, and other covered providers were required to introduce stronger protections for users under 18. (Gov)

As the rules took effect, Australian VPN downloads rose sharply and VPN apps climbed the country’s app-store rankings. (Reuters)

Thousands of people were making the same first move I had made: install a familiar VPN, select a nearby country, and try again.

From the user’s side, every connection looked private and separate.

From the website’s side, many of those users could appear behind the same public IP address.

That was the first reason my innocent session looked suspicious.

I inherited the address and its history

A commercial VPN does not usually give every customer a unique public address.

Many users can leave through the same server. Their sessions remain separate, but websites see one shared IP producing all of the requests.

Most people may be browsing normally. A smaller number may be scraping pages, testing passwords, creating disposable accounts, abusing promotions, or sending automated searches.

The website cannot neatly separate them by looking at the IP.

It sees one address behaving unlike a normal household connection.

Google explains that unusual-traffic warnings can appear when requests from a VPN network resemble automated activity. (Google) The person solving the CAPTCHA may have done nothing wrong. The activity that damaged the address may have come from someone else using the same exit earlier.

That was what I had missed.

The Auckland address was new to me.

Its reputation was not.

“Blacklisted” was not one global verdict

I had imagined a blacklist as a single database containing addresses officially marked as bad.

The reality was more fragmented.

Each website and security provider can make its own decision. One may block an IP completely. Another may show a CAPTCHA. A third may allow browsing but prevent login, payment, posting, or video playback.

Services also use databases that identify VPNs, proxies, hosting providers, and addresses with poor reputations. MaxMind, for example, supplies data that can label an IP as an anonymous VPN, proxy, or hosting address. (Maxmind) Cloudflare offers tools for identifying known VPN infrastructure and managing traffic from risky shared networks. (Cloudflare)

So an address does not need to appear on one universal blacklist.

It only needs to look wrong to the system protecting the page in front of me.

That explained why the same connection produced three different reactions:

The course website blocked it.

Google challenged it.

An IP-checking page loaded normally.

The sites were not contradicting one another. They were applying different thresholds to the same address.

More servers gave me more reputations to test

The established provider had real strengths.

It had years of public history, mature infrastructure, many locations, extensive support material, and a large body of independent reviews. Those were good reasons to trust it with the encrypted connection.

But its server map encouraged me to treat blacklisting as a geography problem.

Auckland failed, so I tried Los Angeles. When that failed, I moved to Singapore, Wellington, and another U.S. city.

Every switch gave me a different IP.

It gave me no reason to believe the next address had a better reputation with the course website.

One server triggered Google’s unusual-traffic warning. Another was recognised as a proxy. A third reached the course dashboard but failed when I opened the video.

The country flags changed.

The pattern did not.

Public discussions describe the same dead end in simpler terms: users clear browser data, change browsers, and rotate through multiple VPN connections while the destination continues rejecting them. (Reddit)

That detail was enough. Once a website had learned to distrust familiar VPN infrastructure, more of the same infrastructure became a lottery.

I did not need the largest selection of exits.

I needed one route the destination would accept.


Turning off the VPN solved the wrong problem

I disconnected and reloaded the course page through my normal Australian connection.

The IP block disappeared.

The age-verification prompt took its place.

The options included a facial estimate and an identity-document process handled by another company.

That confirmed my laptop was not infected. It also left me with two poor choices.

I could expose the destination to my ordinary connection and begin the age check, or I could return to the large VPN and keep searching for an address the site had not already classified.

The first option completed the website’s preferred process.

It did not complete mine.

I wanted to watch a legal video I had paid for without turning the session into another exchange of face images, identity documents, and third-party privacy notices.

At that point, the useful comparison was no longer VPN on versus VPN off.

It was a familiar VPN route that arrived with a damaged reputation versus a route that reached the site without being rejected at the door.

I stopped choosing countries

I closed the course tabs and opened OnlydogVPN.

The smaller app did not begin with a map. Its choices were organised around situations, including services that were restricting or challenging ordinary VPN traffic.

I selected that option and connected before reopening the browser.

Then I launched a fresh private window and pasted the lesson link.

The access-denied page did not appear.

Neither did the CAPTCHA.

The course dashboard loaded with my purchased lessons. I opened the video, moved forward to the section we needed, and let it play.

It continued past the point where the previous servers had failed.

I paused, wrote down the exercise, and reopened the video to check one instruction.

It loaded again.

That was the answer I needed before any technical explanation: the destination accepted the route, and I could finally use the service I had already paid for.

The smaller app uses an obfuscated, HTTP/3-based connection. Instead of sending me through another sequence of familiar country-labelled exits, its situation-based setup treated the rejection itself as the problem.

I did not need to identify which reputation service the course website used.

I needed the page to stop rejecting the connection.

It did.

The blacklist had never been about me

After the video ended, I returned to Google through the same route.

The results loaded without the unusual-traffic interruption that had followed the earlier servers.

That made the difference clear.

A website does not know that the latest person behind an IP is careful, paying, and human. It sees the address, the network it belongs to, the traffic previously associated with it, and whether it resembles known VPN or proxy infrastructure.

When many strangers share one exit, the quiet user inherits the consequences of the loudest ones.

I had not been blacklisted personally.

I had borrowed addresses whose introductions had already gone badly.

The established provider kept offering more of those introductions to test. The smaller app gave me the one that let the conversation begin.

The page became quieter afterward

When I opened the course notes beneath the video, the app’s blocked-request counter increased.

The page was contacting services beyond the video and text I had requested. Some matched advertising and tracking systems and were filtered before they completed.

I could see the counter changing, but I could not inspect the service’s internal filtering rules or determine the purpose of every blocked request.

That filtering was not what removed the IP block. The accepted route had already solved the main problem.

It was a smaller benefit that appeared during the next action. Once the page trusted the connection, fewer outside services joined the session in the background.

The app had not only reached the destination.

It made the visit less crowded afterward.

A large network was not the same as a usable address

The service has fewer locations, a shorter public history, and fewer independent ratings than the established provider I tried first.

Someone who needs a precise city every day may still prefer the larger network.

My problem that evening was not finding Auckland on a map.

I had already found Auckland, Los Angeles, Singapore, Wellington, and several other exits. The website distrusted those addresses before it had any reason to distrust me.

The established provider offered more IPs to test. The smaller app treated the rejection itself as the task and produced the route that completed it.

VPN IP addresses are blacklisted because websites judge the shared address and its history, not the innocence of the latest person using it.

The route that mattered was not the one in the right country.

It was the one that arrived before someone else’s reputation could speak for me.

Questions this experience may leave you with

What was actually causing the problem?

Google explains that unusual-traffic warnings can appear when requests from a VPN network resemble automated activity. ( Google ) The person solving the CAPTCHA may have done nothing wrong. The activity that damaged the address may have come from someone else using the same exit earlier. (Google)

Why did the obvious fixes fail?

I could expose the destination to my ordinary connection and begin the age check, or I could return to the large VPN and keep searching for an address the site had not already classified.

What should you check first?

A website does not know that the latest person behind an IP is careful, paying, and human. It sees the address, the network it belongs to, the traffic previously associated with it, and whether it resembles known VPN or proxy infrastructure.

What finally changed the result?

That was the answer I needed before any technical explanation: the destination accepted the route, and I could finally use the service I had already paid for.

What is worth remembering?

VPN IP addresses are blacklisted because websites judge the shared address and its history, not the innocence of the latest person using it.