CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Detecting a hidden VPN from the browser clock and language

VPN and proxy lists only know the servers they have seen. Residential proxies and brand-new VPN exits look like ordinary home connections. The browser, though, keeps telling the truth about the device: its clock, its languages and sometimes its real IP. This guide explains how to read those signals without flagging honest travelers.

Short answer

Compare the browser time zone and languages with the country of the IP. A clock and a language from another region, on an IP in a high-payout country, is strong evidence of a VPN or proxy, especially with a WebRTC leak or many time zones seen on one IP. Treat it as evidence to combine, not as a ban on its own.

What IP lists miss
Residential proxies and VPN servers that are too new to be listed.
Clock vs IP
A browser time zone in another region than the IP country.
Languages vs IP
Browser languages that name another country, on a high-payout IP.
Strongest sign
Many unrelated time zones seen on the same IP within a week.

Why IP lists are not enough

Most VPN detection starts with lists: ranges owned by hosting companies, the server addresses VPN providers publish, Tor exit nodes, open proxies. Those lists are useful, and CashoutGuard refreshes them every day, but they only know what they have already seen.

The traffic that hurts rewards sites most is exactly what lists miss. Residential proxies route a farm through real home and mobile connections, rented by the hour. A new VPN server is clean until someone reports it. On an offerwall, that traffic converts as if it came from a high-payout country, gets paid, and is reversed weeks later when the advertiser checks quality.

The way around it is to stop asking only "what is this IP" and also ask "does this device belong where the IP says it is". The browser answers that question for free.

The browser clock

Every browser exposes its time zone, such as Asia/Kolkata or America/New_York. A phone or computer sets it from its location or the network, and most people never touch it. A VPN changes the IP, not the clock. So a device in India browsing through a US exit still reports Asia/Kolkata.

IP countryBrowser time zoneReading
United StatesAmerica/ChicagoConsistent
United StatesAsia/KolkataDevice very likely in India: VPN or proxy
United KingdomEurope/LisbonSame offset in winter: weak, not a mismatch
GermanyAfrica/CairoDifferent region and offset: strong mismatch

Each time zone name maps to a country, so the comparison is between two countries, plus their offsets. When the IP database has no time zone for an address, the fallback question is whether any time zone of the IP country has the same offset as the browser. If one does, there is no mismatch.

Two details keep this honest. Compare regions and UTC offsets, not just names, because neighboring countries often share an offset. And give more weight when the IP is in a country that pays more than the one the clock points to: that is the direction fraud goes, since nobody gains from faking a lower-paying country.

Browser languages

Browsers also send the user's preferred languages, often with a region: es-MX, ar-EG, hi-IN. A list that starts with ar-EG on an IP in the United States or Italy says the device is set up for Egypt. On its own that is weak, because people live abroad, but together with the clock it is a second, independent witness.

  • Ignore en-US and en-GB: they are browser defaults everywhere and say nothing.
  • Allow large local communities: Spanish in the US, French in Canada, Arabic in the Gulf states.
  • Count it only on IPs in high-payout countries, where faking the location pays.
  • Give it more weight when the first language names another country and is not English.

WebRTC leaks and one IP with many time zones

Some VPN setups leak the real IP through WebRTC, the browser feature used for video calls. When the browser reveals a second public IP in another country than the one making the request, the device is behind a tunnel. That is close to proof, and it is weighted accordingly.

The strongest residential proxy signal comes from looking across users instead of one device. A home connection belongs to one household, so it shows one or two time zones. A proxy exit is shared by strangers from all over the world, so the same IP shows Asia/Manila, Africa/Lagos and America/Bogota in the same week. Three or more unrelated time zones on one IP is a proxy, whatever the IP lists say.

Proxy exits move between websites, so this check works better when the history is pooled: CashoutGuard counts the time zones seen on an IP across every site it protects, and keeps only the count, never which site saw what.

False positives to avoid

  • Travelers and expats: phones update their time zone when they land, but laptops and some users do not. Treat a mismatch alone as a reason to review, not to block.
  • Privacy relays: iCloud Private Relay hides the real location on purpose and is used by ordinary iPhone owners. Recognize relay ranges and skip the comparison for them.
  • Border regions and shared offsets: compare offsets and regions, never just country names.
  • Apps in WebViews: some apps set the language themselves. Check the language signal against your own app traffic before giving it weight.

The rule that keeps false positives low is simple: no single browser signal blocks anyone. A clock mismatch plus a foreign language plus a high-payout IP is a pattern. Any one of them alone is a question.

How CashoutGuard does it

The browser script collects the time zone, languages and WebRTC candidates, and the server compares them with the IP on every event. The reasons appear as timezone_mismatch, locale_country_mismatch, webrtc_ip_leak and ip_multi_timezone, each with the evidence (the browser zone, the languages, the countries) so a reviewer can see why. Weights rise when the IP is in a high-payout country and the device points elsewhere.

You can check what an IP looks like on its own with the free IP checker, and the Traffic page shows how much of your traffic looks residential but hides a VPN. New sites start in shadow mode, so you see the effect before anything is blocked.

Frequently asked questions

Can a user fake the browser time zone?

Yes, with effort, and anti-detect browsers do. That is why the clock is compared with the language, WebRTC and the time zones other users showed on the same IP. Faking all of them consistently is much harder.

Does this work on mobile apps?

In a WebView, yes: the same browser signals are available. In a native app, use the Android library, which reads the device time zone and locale directly.

Should I block every mismatch?

No. Use it to review, and block only when it comes with other evidence such as a WebRTC leak, many time zones on the IP or accounts linked by device or wallet.

Keep reading