Detecting a hidden VPN from the browser clock and language
VPN and proxy lists only know the servers they have seen. Residential proxies and brand-new VPN exits look like ordinary home connections. The browser, though, keeps telling the truth about the device: its clock, its languages and sometimes its real IP. This guide explains how to read those signals without flagging honest travelers.
Short answer
Compare the browser time zone and languages with the country of the IP. A clock and a language from another region, on an IP in a high-payout country, is strong evidence of a VPN or proxy, especially with a WebRTC leak or many time zones seen on one IP. Treat it as evidence to combine, not as a ban on its own.
- What IP lists miss
- Residential proxies and VPN servers that are too new to be listed.
- Clock vs IP
- A browser time zone in another region than the IP country.
- Languages vs IP
- Browser languages that name another country, on a high-payout IP.
- Strongest sign
- Many unrelated time zones seen on the same IP within a week.
Why IP lists are not enough
Most VPN detection starts with lists: ranges owned by hosting companies, the server addresses VPN providers publish, Tor exit nodes, open proxies. Those lists are useful, and CashoutGuard refreshes them every day, but they only know what they have already seen.
The traffic that hurts rewards sites most is exactly what lists miss. Residential proxies route a farm through real home and mobile connections, rented by the hour. A new VPN server is clean until someone reports it. On an offerwall, that traffic converts as if it came from a high-payout country, gets paid, and is reversed weeks later when the advertiser checks quality.
The way around it is to stop asking only "what is this IP" and also ask "does this device belong where the IP says it is". The browser answers that question for free.
The browser clock
Every browser exposes its time zone, such as Asia/Kolkata or America/New_York. A phone or computer sets it from its location or the network, and most people never touch it. A VPN changes the IP, not the clock. So a device in India browsing through a US exit still reports Asia/Kolkata.
| IP country | Browser time zone | Reading |
|---|---|---|
| United States | America/Chicago | Consistent |
| United States | Asia/Kolkata | Device very likely in India: VPN or proxy |
| United Kingdom | Europe/Lisbon | Same offset in winter: weak, not a mismatch |
| Germany | Africa/Cairo | Different region and offset: strong mismatch |
Each time zone name maps to a country, so the comparison is between two countries, plus their offsets. When the IP database has no time zone for an address, the fallback question is whether any time zone of the IP country has the same offset as the browser. If one does, there is no mismatch.
Two details keep this honest. Compare regions and UTC offsets, not just names, because neighboring countries often share an offset. And give more weight when the IP is in a country that pays more than the one the clock points to: that is the direction fraud goes, since nobody gains from faking a lower-paying country.
Browser languages
Browsers also send the user's preferred languages, often with a region: es-MX, ar-EG, hi-IN. A list that starts with ar-EG on an IP in the United States or Italy says the device is set up for Egypt. On its own that is weak, because people live abroad, but together with the clock it is a second, independent witness.
- Ignore en-US and en-GB: they are browser defaults everywhere and say nothing.
- Allow large local communities: Spanish in the US, French in Canada, Arabic in the Gulf states.
- Count it only on IPs in high-payout countries, where faking the location pays.
- Give it more weight when the first language names another country and is not English.
WebRTC leaks and one IP with many time zones
Some VPN setups leak the real IP through WebRTC, the browser feature used for video calls. When the browser reveals a second public IP in another country than the one making the request, the device is behind a tunnel. That is close to proof, and it is weighted accordingly.
The strongest residential proxy signal comes from looking across users instead of one device. A home connection belongs to one household, so it shows one or two time zones. A proxy exit is shared by strangers from all over the world, so the same IP shows Asia/Manila, Africa/Lagos and America/Bogota in the same week. Three or more unrelated time zones on one IP is a proxy, whatever the IP lists say.
Proxy exits move between websites, so this check works better when the history is pooled: CashoutGuard counts the time zones seen on an IP across every site it protects, and keeps only the count, never which site saw what.
False positives to avoid
- Travelers and expats: phones update their time zone when they land, but laptops and some users do not. Treat a mismatch alone as a reason to review, not to block.
- Privacy relays: iCloud Private Relay hides the real location on purpose and is used by ordinary iPhone owners. Recognize relay ranges and skip the comparison for them.
- Border regions and shared offsets: compare offsets and regions, never just country names.
- Apps in WebViews: some apps set the language themselves. Check the language signal against your own app traffic before giving it weight.
The rule that keeps false positives low is simple: no single browser signal blocks anyone. A clock mismatch plus a foreign language plus a high-payout IP is a pattern. Any one of them alone is a question.
How CashoutGuard does it
The browser script collects the time zone, languages and WebRTC candidates, and the server compares them with the IP on every event. The reasons appear as timezone_mismatch, locale_country_mismatch, webrtc_ip_leak and ip_multi_timezone, each with the evidence (the browser zone, the languages, the countries) so a reviewer can see why. Weights rise when the IP is in a high-payout country and the device points elsewhere.
You can check what an IP looks like on its own with the free IP checker, and the Traffic page shows how much of your traffic looks residential but hides a VPN. New sites start in shadow mode, so you see the effect before anything is blocked.