FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Website Detected My VPN—But That Wasn’t the Same as Tracing Me

The warning appeared just as I attached the last photograph:

VPN or proxy detected. Disable it to continue.

I was trying to send a confidential tip to a local newspaper about conditions in my apartment building. The heating had failed repeatedly, water had entered two flats, and the landlord’s public statements did not match the emails residents had received.

I did not want my name in the article. I also did not want the submission immediately connected to the home broadband account registered at the same building.

I had turned on a well-known VPN, opened a private window, and assumed that was enough. Instead, the form recognised the connection before I could press Submit.

My first thought was not that the server had been blocked.

It was: If the website can detect my VPN, can it trace me through it?

I changed to another server in the same country and tried again. The warning returned.

That second rejection made the question feel less theoretical. I had hidden my home IP address, yet the website still knew enough to stop me.

The short answer

Public discussions about VPN tracing often arrive at the same uncomfortable point: people hide their IP address, then identify themselves again through an account or a browser full of familiar signals. ( Reddit )

Detection is not the same as identification

The question has become more urgent in the UK since stronger age-assurance requirements took effect in July 2025. Daily VPN use more than doubled afterward, peaking above 1. (MDN) million users. By July 2026, government consultations were discussing whether platforms should detect VPN-based circumvention and whether VPN services themselves could be age-gated. (Gov)

Words such as detect and prevent make it sound as though a website can follow a VPN tunnel backward until it reaches a named person.

Usually, the site is doing something simpler.

A website sees the address where traffic emerges onto the public internet. With a VPN, that is the exit server rather than the IP address assigned to the user’s home. If thousands of people use the same exit, the address becomes easy to recognise.

The site may find it in a commercial VPN database. It may notice that many unrelated visitors share it. It may see that the address belongs to a data centre rather than a residential internet provider.

That is enough to label the connection as a VPN. It is not enough, by itself, to identify the person behind it.

The internet provider sees the other end of the journey. It can see the home connection communicating with a VPN server, along with the timing and volume of the traffic. It cannot directly see the destinations carried inside the encrypted tunnel. (Eff)

The two sides therefore hold different pieces:

  • The ISP sees the connection entering the tunnel.
  • The website sees it leaving.
  • The VPN prevents the ordinary home IP and the destination from appearing together.

That is the protection I needed for the tip. But the failed form showed that hiding the route would not help if the connection itself was immediately classified and refused.

The tunnel was not my only trace

The first provider had built an encrypted route correctly. Its problem was visibility.

Many established VPNs rely on familiar server ranges and traffic patterns. Researchers have shown that common VPN protocols can be recognised even when the contents remain encrypted. (Usenix) A site does not need to break the encryption to decide that the visitor is using a VPN.

More importantly, an IP address is only one way to connect a session to a person.

An account login can do it. So can an old cookie, a personal email address, a phone number, payment information, or a browser that exposes the same characteristics on every visit.

Browser fingerprinting combines details such as language, time zone, screen properties, software versions, fonts, and device configuration. Those signals remain available after an IP address changes. (MDN)

That explained why my private window had helped less than I expected. It reduced some stored browser history, but it did not change the VPN account I had created with my regular email. It also did nothing to make the provider’s exit addresses less familiar to the newspaper’s security system.

Public discussions about VPN tracing often arrive at the same uncomfortable point: people hide their IP address, then identify themselves again through an account or a browser full of familiar signals. (Reddit)

I had been concentrating on one trace while carrying several others through the tunnel.

Once that became clear, repeatedly changing cities in the server menu looked like the wrong response. I did not need a more distant exit. I needed fewer links that could be matched together—and a connection the form would actually accept.

The established provider gave me more rejected exits

I had chosen the major service for sensible reasons.

It had years of public history, a large support operation, many independent reviews, and servers across dozens of countries. Those strengths would matter if I needed a specific location or broad international coverage.

For this submission, they did not solve the immediate failure.

The newspaper recognised both exit servers I tried. Large shared server pools concentrate many users behind the same addresses, making those exits easier for websites to classify and block. (Cloudflare)

The setup also began with a conventional account. I had entered my regular email address, created a password, selected a subscription, and supplied payment information.

None of that was visible to the newspaper. But it added another durable identity around a task I was deliberately trying to separate from my everyday life.

The provider had hidden my home IP, but its recognisable exits prevented me from reaching the submit button. Offering more cities only gave me more places to repeat the same attempt.

That changed the comparison completely.

For a confidential submission, an ordinary-looking, reachable connection mattered more than a large catalogue of exits.


The second connection reached the form

I cleared the failed submission, closed the browser, and opened a separate profile containing none of my regular accounts, extensions, or stored cookies.

Then I opened OnlydogVPN.

The smaller app offered a situation-based option for networks or websites that restrict recognisable VPN traffic. Basic use also did not require a conventional email-and-password account.

I connected and returned to the newspaper’s tip page.

The warning did not appear.

I attached the photographs again, pasted the timeline of repair requests, and entered a contact alias created only for the submission. The form moved to the final page.

I pressed Submit.

A reference number appeared.

That confirmation answered the question more usefully than another explanation of VPN theory could have.

In this test, the service’s HTTP/3-based transport and additional obfuscation reached a form that had rejected the familiar VPN exits. The newspaper received the submission from the VPN address rather than my home connection, and the VPN setup had not required my everyday email.

The important result was not that I had become impossible to trace. It was that the unnecessary links had been removed.

My ISP did not see the newspaper as the destination. The newspaper did not receive my home IP. The clean browser profile did not carry my normal accounts or cookies. The VPN itself had not begun by asking me to create another conventional identity.

The tip was now separated from the parts of my online life that had nothing to do with it.

The page was still inviting other observers

After submitting the tip, I stayed on the newspaper’s site to read its explanation of how confidential sources were handled.

While the page loaded, the app’s blocked-request counter increased.

The site was contacting services beyond the article and submission pages I had intentionally opened. Some requests supported normal page functions. Others matched advertising or tracking systems and were filtered by the service.

This was a different problem from hiding the destination from my ISP.

A standard VPN would carry those tracking requests through the encrypted tunnel along with everything else. The broadband provider would not see the individual destinations, but the third parties at the other end could still receive browser and page information.

The smaller app reduced those extra connections before they left the device. The counter made the difference visible without asking me to read a technical log.

I could see that requests were being blocked, but I could not inspect the service’s internal filtering rules or determine the purpose of every connection it rejected.

The submission had already succeeded, so this was not another condition the app needed to pass. It was a smaller discovery afterward: once the obvious route had been hidden, fewer background services were being allowed to watch the session around it.

That gave me a reason to keep the app installed after the reference number arrived.

What a VPN hides—and what can still lead back to you

The service has fewer locations, a shorter public history, and fewer independent ratings than the established provider. Someone who needs a precise exit country may still value the larger network.

But the newspaper had not rejected my first attempt because I lacked countries to choose from. It had recognised the exits I was using, while my account and browser created other links that an IP change could not remove.

A VPN can be detected. A server can be identified as belonging to a VPN service. A user can still reveal themselves through logins, cookies, payments, browser fingerprints, or information included in a submission.

What the VPN hides is narrower but crucial: the direct connection between the user’s ordinary internet address and the destination.

The major provider encrypted that connection but could not get me past the form. The smaller app made the protected traffic less conspicuous, required less identity at setup, and allowed the tip to reach the newsroom.

For the submission I was trying to make, traceability was not decided by how many servers I could hide behind. It was decided by how few usable links I left between the tip and the person sending it.

Questions this experience may leave you with

What was actually causing the problem?

Public discussions about VPN tracing often arrive at the same uncomfortable point: people hide their IP address, then identify themselves again through an account or a browser full of familiar signals. ( Reddit ) (Reddit)

Why did the obvious fixes fail?

The newspaper recognised both exit servers I tried. Large shared server pools concentrate many users behind the same addresses, making those exits easier for websites to classify and block. ( Cloudflare ) (Cloudflare)

What should you check first?

In this test, the service’s HTTP/3-based transport and additional obfuscation reached a form that had rejected the familiar VPN exits. The newspaper received the submission from the VPN address rather than my home connection, and the VPN setup had not required my everyday email.

What finally changed the result?

The smaller app offered a situation-based option for networks or websites that restrict recognisable VPN traffic. Basic use also did not require a conventional email-and-password account.

What is worth remembering?

A VPN can be detected. A server can be identified as belonging to a VPN service. A user can still reveal themselves through logins, cookies, payments, browser fingerprints, or information included in a submission.