1. Network, VPN, & Geolocation Evading Vectors
WebRTC Network Leak
Detection approach
The visitor's browser leaked their actual residential IP address through a WebRTC socket connection, bypassing their active HTTP/S proxy or VPN setup. Anti-detect browsers and commercial proxy extensions frequently fail to tunnel UDP-based WebRTC traffic, leaving the visitor's true, un-proxied ISP connection exposed. This network discrepancy provides ironclad proof that the visitor is actively attempting to evade geographical ad filters to submit fraudulent clicks while hiding their true location. (Note: Active client-side WebRTC local IP gathering is deactivated to prevent triggering macOS/iOS local network permission prompts; WebRTC leakage is checked where natively available or via browser APIs).
How this helps detect bots
This signal is assessed with other independent session, browser, and network evidence. A single anomaly is a lead, not a verdict; corroborating anomalies make automated traffic more likely.
Legitimate traffic to consider
Legitimate privacy-focused users running commercial VPNs on Windows or macOS where OS-level WebRTC queries leak the real ISP IP.