← Back to Blog

Anti-Detect Browser on VPS: 6 Places Where Real IP Leaks Occur and How to Fix Them

A VPS with an anti-detect browser seems like a reliable setup for multi-accounting, but the real server IP can leak in six places. We analyze each one and show how to close the gaps.

📅October 2, 2026

Arbitrage specialists and SMM professionals are moving anti-detect browsers to VPS to obtain a stable IP, not depend on home internet, and work from anywhere in the world. The logic is correct, but in practice, the combination of VPS + Dolphin Anty, AdsPower, or GoLogin often reveals the real IP of the server bypassing the proxy — and the platform sees a mismatch that leads to a ban. We analyze six specific leak points and show how to close them.

Why VPS Does Not Guarantee Anonymity on Its Own

Many arbitrage specialists think: “I took a VPS in the Netherlands, so my traffic comes from the Netherlands.” This is not true. A VPS is simply a remote computer with its own IP address from the hosting provider (this is a datacenter IP, which is easily detected by anti-fraud systems of Facebook, TikTok, and Google). An anti-detect browser substitutes the device fingerprint, but not the entire network stack of the operating system. If you set the proxy only within the browser itself and not at the level of the entire VPS system, part of the traffic — DNS, WebRTC, system updates — may go directly through the server's IP, bypassing the proxy.

The result is that Facebook Ads or TikTok Ads sees that “the browser accessed from an IP in the Netherlands,” while the DNS request or WebRTC packet came from the datacenter IP in the USA. This is a classic signal for the anti-fraud algorithm, which leads to an immediate ban of the advertising account, even if you used an expensive residential proxy. Let’s analyze where this discrepancy occurs.

Leak 1: WebRTC Reveals the Real IP of the Server

WebRTC is a technology used for video calls and P2P connections directly in the browser. The problem is that WebRTC can obtain the real local and public IP address of the device, even if all other browser traffic goes through a proxy. This is one of the most common sources of IP leaks on VPS — a script on the page makes a STUN request and receives the real IP of the hosting server in response.

Most anti-detect browsers — Dolphin Anty, AdsPower, Octo Browser — have built-in WebRTC protection with modes “Altered” (substitution with proxy IP) or “Disabled” (complete shutdown). Make sure that the substitution mode is selected in the profile, not “Real” — this setting by default in some builds reveals the real IP. You can check for leaks through any public WebRTC leak test service: if your VPS provider's IP pops up there instead of the proxy IP — you urgently need to change the profile setting.

Leak 2: DNS Requests Bypass the Proxy

When the browser opens facebook.com, it first makes a DNS request to find out the IP address of the domain. If the proxy is configured only at the HTTP/HTTPS traffic level (and not as SOCKS5 with full tunneling), the DNS request may go through the system resolver of the VPS directly to the DNS server of the hosting provider. The platform or third-party tracking script records that the DNS request came from the country of the datacenter, while the HTTP traffic came from the country of the proxy. This is called a DNS leak, and it is as dangerous as a leak through WebRTC.

To avoid this, use SOCKS5 proxies instead of HTTP where possible — SOCKS5 tunnels all traffic, including DNS resolution. In the settings of the anti-detect browser (Multilogin, GoLogin, Incogniton), choose the proxy type SOCKS5 and make sure to enable the option “Resolve DNS through proxy,” if available. You can check for DNS leaks with a separate test: open a profile with a proxy and see what IP the DNS leak test shows — it should match the geo of the proxy, not the geo of the VPS.

Leak 3: Timezone and Locale of VPS Do Not Match the Geo of the Proxy

This is not an IP leak in the literal sense, but it works in the same direction — revealing the real location of the server. If you bought a residential proxy with a geo of Germany, but the VPS itself is physically located in a datacenter in the Netherlands with a system timezone of UTC+1 and locale nl-NL, the browser may pull the timezone and language from the OS system, not the proxy. Anti-fraud systems of Facebook and TikTok compare geolocation by IP with the browser's timezone (the Intl.DateTimeFormat attribute), and a discrepancy of 1-2 hours is another red flag.

The solution is to manually set the timezone, interface language, and geolocation in each anti-detect browser according to the geo of the proxy, rather than relying on auto-detection “by system.” In Dolphin Anty and AdsPower, this is done in the profile settings under Timezone/Geolocation — choose “Based on IP” instead of “Based on OS,” then the browser will pull the correct parameters according to the proxy IP.

Leak 4: Background Processes and OS Updates

On a VPS with Windows or Linux, background processes are constantly running: system auto-updates, antivirus, time synchronization (NTP), telemetry of the OS itself. All these processes make network requests directly through the system IP, bypassing the proxy that is set only in the browser. These requests are not directly related to the advertising account, but if there is tracking or analytics software on the VPS that checks the device IP against the browser session IP (this is done by some advanced anti-fraud scripts of marketplaces and advertising platforms), the discrepancy will be recorded.

Practical advice: disable Windows auto-updates on the VPS, turn off unnecessary background services, and if the VPS provider allows it, set up a system proxy at the OS level (through the network control panel), not just in the browser. This is especially important if you manage 10-50 client accounts and use one VPS for several anti-detect browser profiles simultaneously.

Leak 5: TCP/IP Fingerprint and Network Metrics

A more subtle leak is the analysis of TTL (Time To Live), MTU, and other parameters of the TCP/IP stack of the VPS operating system. Advanced anti-fraud systems, including those of Facebook Ads and TikTok Ads, can correlate these metrics with the declared geo of the proxy. For example, the typical TTL for Windows Server in a datacenter differs from the TTL of a regular home router in the same country — and this creates another layer of fingerprinting that is not masked by the anti-detect browser, because it operates at the OS network stack level, not the browser level.

This leak is not critical for most SMM and scraping tasks, but becomes significant when scaling the farming of advertising accounts. A partial solution is to use mobile proxies instead of residential ones where maximum similarity to real user traffic is critical: mobile IPs are less associated with datacenters and are less likely to trigger in-depth network analysis.

Leak 6: Telemetry of the Anti-Detect Browser Itself

Many forget that the anti-detect browser itself is a separate application that periodically checks for updates, sends usage statistics, or synchronizes profiles with the developer's cloud (this is relevant for Dolphin Anty, AdsPower, GoLogin with cloud synchronization of the team). These service requests often go directly through the system IP of the VPS, not through the proxy tied to a specific profile.

This leak does not directly reveal the real IP of the user to the platform, but if you have firewall monitoring or work in a jurisdiction with strict network hygiene requirements, it is worth checking the auto-update settings in the anti-detect browser application itself and, if possible, disabling background synchronization when working with sensitive accounts.

Checklist: How to Check VPS Before Launching Accounts

Before launching advertising campaigns or managing client accounts through a VPS with an anti-detect browser, go through a simple checklist:

Check What Should Match
WebRTC leak test IP from the test = Proxy IP, not VPS provider IP
DNS leak test DNS server in geo of proxy, not in geo of datacenter
Browser timezone Matches geo of proxy (Based on IP mode)
System language and locale Matches the language of the proxy country
OS auto-updates Disabled or configured through system proxy
Proxy type in profile SOCKS5 with full DNS tunneling

Perform this check for each new profile, especially if you are scaling the farming of accounts on a new VPS or transferring client working profiles to another server.

Which Proxies to Choose for Working with VPS

The choice of proxy type directly affects how often the described leaks will occur and how significantly this will impact bans. For farming advertising accounts on Facebook Ads and TikTok Ads, most arbitrage specialists choose residential proxies — they use real IPs of home users, and even if the timezone or DNS diverges by milliseconds, the traffic fingerprint still looks natural to anti-fraud systems.

For tasks where maximum similarity to mobile users is important — for example, farming TikTok or Instagram accounts, which traditionally access from a phone — mobile proxies are better suited. They are less likely to trigger the in-depth network analysis described in the TCP/IP fingerprint section because mobile operators provide dynamic, frequently changing IPs that resemble real user behavior.

If the task is not accounts but scraping prices on Wildberries, Ozon, or monitoring competitors on Avito, where speed and stability are important, rather than disguising as a human, it is wiser to use datacenter proxies — they are faster and handle large volumes of requests without the risk of account bans (scraping usually goes without account authorization).

Conclusion

A VPS with an anti-detect browser is a working combination for multi-accounting, but it requires attention to detail at the system level, not just the profile settings in Dolphin Anty, AdsPower, or GoLogin. The real IP of the server can leak through WebRTC, DNS requests, timezone mismatches, background OS processes, TCP/IP fingerprints, and the telemetry of the browser itself. Each of these leaks is a separate reason for banning an advertising account or suspicious activity on a marketplace.

Check profiles against the checklist before each campaign launch, set up SOCKS5 DNS tunneling, and choose the type of proxy for the specific task. For farming advertising accounts and managing social media, we recommend starting with residential proxies — they provide the best balance between anonymity, speed, and resilience to anti-fraud measures, minimizing the risk that the leaks mentioned in the article will lead to a ban.