← Back to Blog

Illegal VPN Addresses: SCREEN Act, Utah SB 73, and IP Proxy Blocking

On August 5, 2026, the U.S. Senate Commerce Committee failed the SCREEN Act due to a lack of quorum — the first federal bill that directly requires checking traffic from "known VPN addresses." However, a similar regulation has been in effect in Utah since May 6. Let's analyze how VPN-IP lists are structured, why they make mistakes, and what changes for data center, residential, and mobile proxies.

📅August 7, 2026
Illegal VPN Addresses: SCREEN Act, Utah SB 73, and IP Proxy Blocking

On August 5, 2026, the U.S. Senate Commerce Committee marked up five "children's" internet bills. Four passed: the Kids Online Safety Act, the CHATBOT Act, the Youth AI Privacy Act by Senator Edward Markey, and the Children's Artificial Intelligence Toy Safety Act by Senator Tammy Duckworth. The fifth bill, the SCREEN Act, received 15 votes in favor and 13 against but did not advance out of committee due to a lack of quorum at the time of the vote.

This is significant news for the proxy industry. The SCREEN Act is the first federal bill in the U.S. that explicitly includes the category of "known VPN addresses" in the text of the law and requires age verification for them. While the federal level is stalled in procedure, a similar provision is already in effect at the state level: Utah's SB 73 took effect on May 6, 2026.

What the SCREEN Act Requires from IP Addresses

The SCREEN Act is S. 737 in the 119th Congress, officially titled the Shielding Children's Retinas from Egregious Exposure on the Net Act. It was authored by Senator Mike Lee, with co-sponsors John Curtis, Jim Banks, and James Lankford. The bill was introduced on February 26, 2025, and remained inactive until August 2026.

The mechanics are as follows. Services are required to implement "technological verification measures" for users by determining their location via IP address, unless they can ascertain that the user is outside the U.S. Additionally, the law mandates that traffic from known VPN addresses undergo verification. A simple checkbox stating "I am over 18" is insufficient; the law clearly indicates that self-declaration is not enough, and methods tied to real identity are necessary.

The Electronic Frontier Foundation, in an analysis dated July 31, 2026, points out two side effects. The first is the scope: the language is written in such a way that it encompasses virtually any service that contains even a fragment of explicit content, including Netflix, Reddit, Discord, and Bluesky. The second is data retention: the protective requirements for collected documents are vaguely defined, allowing companies to retain them for as long as they deem reasonable.

Utah: A Law That Is Already Working

The federal bill is still just an intention. However, SB 73 "Online Age Verification Amendments," signed by Utah Governor Spencer Cox on March 19, 2026, has been in effect since May 6.

Utah approached the issue from an unexpected angle—not by banning VPNs for users, but by holding websites accountable. According to SB 73, a user is considered to be accessing from Utah if they are physically present there, regardless of what proxy or VPN is masking their IP. The responsibility for verification remains with the website even when the visitor has altered their geolocation. Additionally, there is a specific prohibition: platforms with a significant amount of content harmful to minors are not allowed to publish instructions on bypassing checks via VPN.

NordVPN has referred to this structure as a "trap of responsibility" and an "insurmountable compliance paradox." The logic is simple: if a website cannot reliably determine a person's real location behind a VPN, and the law requires this to be done, it has two options—either block all IPs marked as VPNs and proxies or require verification from all visitors worldwide. Both options go far beyond the original task.

Utah has become the first state where this is codified into law. Wisconsin attempted to go further by explicitly prohibiting VPNs in SB 130 / AB 105, but after public criticism, Senator Van Wanggaard removed this provision in February 2026, and the bill was sent to the governor without it. According to the Free Speech Coalition, age verification laws have been passed in 25 states, with approximately 15 more under consideration.

How the Lists of "Known VPN Addresses" Are Structured

The most interesting aspect of these laws is that they rely on technology that is not described within the laws themselves. A "known VPN address" is not a legal fact but a string in a commercial IP reputation database. Services like IPQualityScore, IPinfo, and ipgeolocation.io sell such lists, which are compiled from several layers.

  • ASN mapping. Ranges are matched with data from regional internet registrars: determining whether the address belongs to a host or a residential provider.
  • Published cloud ranges. AWS, DigitalOcean, OVH, and others publish their networks. Commercial VPN servers are almost always located there rather than on residential lines, making the entire data center pool suspicious by default.
  • Reverse DNS and name patterns. Typical PTR records from hosting reveal infrastructure just as well as ASN.
  • Behavioral signals. Anomalous density of different users on a single address, mismatches between IP geolocation and time zone, and client language.

According to vendor claims, systems against known commercial VPN endpoints achieve over 95% accuracy with false positive rates below 1% on residential networks. This sounds good until that 1% is multiplied by the entire traffic of the country.

Where the Lists Miss

False positives in IP reputation are not a rarity but a structural feature. Typical sources of errors include:

  1. Address reuse. An IP that hosted a VPN endpoint last month may now be assigned to a regular business. It remains marked in outdated blacklists.
  2. CGNAT by providers. Operators hide thousands of subscribers behind a single address, and atypical ASN patterns cause classifiers to mistake residential users for proxies.
  3. Mobile operators. Some cellular traffic is routed through infrastructure adjacent to data centers, leading to suspicion.
  4. Corporate VPNs. Technically, they are indistinguishable from consumer VPNs: the same tunnel, the same hosting exit address.

Currently, such a list is an anti-fraud tool, where an error results in one extra captcha. When it becomes a compliance tool, an error leads to denial of access—and the site has no motivation to investigate because the penalty is for a missed check, not for over-caution. This is why regulatory pressure always shifts thresholds toward more aggressive blocking. A detailed analysis of how platforms classify addresses and distinguish residential traffic from infrastructure traffic can be found in our article on IP intelligence and residential proxy detection.

Who Else Will Be Affected Besides the Target Audience of the Law

Formally, the SCREEN Act and SB 73 are written about adult content. Practically, they change the economics of blocking for the entire internet at once—because a site does not build a separate detection layer "for compliance" and a separate one "for everything else." It purchases one IP reputation database and applies it to all traffic.

Consequently, everything that operates on infrastructure addresses suffers:

  • Data collection and monitoring. Price parsing, checking search results by regions, tracking inventory—tasks where the data center pool has historically been the cheapest solution.
  • Local search and advertising verification. Agencies need to see a page from the perspective of a user from a specific state or country; an aggressive VPN filter disrupts this.
  • Multi-accounting and SMM. Platforms already treat the "proxy" indicator as a risk signal during registration and login, even without new laws.
  • Regular users of corporate tunnels. An employee using a work VPN appears to a site the same as someone hiding their location.

What This Means for Proxy Type Selection

The main practical conclusion is that the gap between infrastructure and residential addresses will only grow, determined not by traffic quality but by the origin of the IP.

Data center proxies are the first to be listed and almost automatically: their ASN is publicly known, and ranges are published by the hosts themselves. This remains the fastest and cheapest option for platforms indifferent to the type of address—internal APIs, parsing loyal sources, load testing. However, using them where VPN checks are in place is becoming increasingly pointless.

Residential proxies operate through real subscriber lines of home providers: by ASN, they belong to regular ISPs, and this traffic does not fall into the "known VPN address" category. This makes them a viable option where IP origin checks are tightening.

Mobile proxies rely on pools from cellular operators, where dozens and hundreds of subscribers naturally share one address. This is why blocking such addresses is the most costly for platforms: the price of a false positive is measured not by one visitor but by the entire pool.

At the same time, no type of address negates other detection signals—TLS fingerprints, browser behavior, header consistency, and time zone. Changing the IP solves only one part of the problem; we discussed what the rest looks like in our analysis of British initiatives on VPN restrictions.

Where the Situation Is Heading Beyond the U.S.

The American story is part of a broader shift. Australia launched a ban on social media for children under 16 on December 10, 2025, Malaysia followed on June 1, 2026, Brazil's regulation took effect in March 2026, and Turkey restricted access for users under 15 in April 2026. The European Parliamentary Research Service has noted a significant increase in VPN usage to bypass age checks, and in the UK, there is a discussion about the idea of restricting access to VPN services themselves based on age.

The overall trend is clear: regulators first demand age verification, then discover that verification is circumvented by changing IPs, and the next step is to try to close the very possibility of changing IPs. The legal language always lags behind technology—the term "known VPN address" remains a reference to a commercial database that no one is obligated to publish or contest.

Conclusion

The failure of the SCREEN Act on August 5 is a delay in procedure, not a cancellation of the course: the bill garnered a majority of votes and did not pass only due to absences. A real precedent has already been set in Utah, where the responsibility for users behind VPNs has rested with the website since May 6, 2026, and the logic of this law is pushing platforms toward total blocking of marked addresses.

For those using proxies in their work, the practical takeaway is that infrastructure addresses are decreasing in cost while increasing in risks, and the reliability of access increasingly depends on where the IP is physically sourced from. It is essential to check not the claimed speed of the pool but its origin and how it appears in IP reputation databases—because it is these databases that the law now references.