Skip to content
VPNmine
LEAKS AND TESTING

How accurate is IP geolocation?

Country-level accuracy is high, commonly quoted around 95 to 99 percent. City-level accuracy is much lower and varies enormously by country and connection type. Geolocation is a lookup in a database of registrations rather than a measurement, so it reports where a block was allocated.

4 min read

Illustration of a map pin and a target, joined by a dashed tunnel line on a dark grid.

There is no location field in an IP packet. Geolocation is entirely inference, built from registry records, routing announcements, latency measurements and data volunteered by networks. Understanding that explains every one of its characteristic errors.

The accuracy that is usually quoted

Vendors claim roughly 95 to 99 percent at country level and something like 50 to 80 percent at city level, within a radius of a few tens of kilometres.

Both numbers are averages across an enormous variance. Country accuracy is high because address blocks are allocated by regional registries along national lines, and it holds well. City accuracy in a dense European or North American market is decent. In a large country with centralised allocation, it can be close to useless.

Where the data comes from

Registry records. Every block is registered to an organisation, with an address. That is often a corporate headquarters rather than where the addresses are used.

Routing announcements. Which network announces a block, and from where, is public and updated continuously.

Latency measurement. Some vendors probe from known locations and triangulate from round-trip times, which is the only input that measures physical reality.

ISP-supplied data. Some networks provide vendors with their own allocation maps, which is the most accurate source and is available only where a network chooses to cooperate.

Why mobile is so bad

Mobile carriers assign addresses from pools attached to gateways serving huge areas, sometimes an entire country. Your handset can be placed hundreds of kilometres away, and the answer will not change as you travel.

Add carrier-grade NAT, where thousands of subscribers share one address, and the whole concept of a location for that address stops meaning anything.

Why VPN and datacentre addresses are a special case

A VPN server sits in a datacentre, and the datacentre's block is registered to a hosting company. Vendors classify these ranges specifically, which is how a streaming service concludes you are on a VPN.

Two consequences. The country reported for a VPN exit is usually accurate, because hosting allocations are clean. And the address is flagged as non-residential regardless of where it is, which is a separate signal from location and is the one that triggers proxy detection.

The failure everyone has met

An address whose registry record points at a company's head office, so a user in one city is placed in another. Or a block reassigned between datacentres whose record has not been updated in a year. Or a satellite connection placed at the ground station.

If a website insists you are somewhere you are not, this is why, and there is usually nothing you can do beyond asking the vendor to correct the record — which several offer as a public form.

What it means practically

For services applying regional rules, the database answer is the truth, because the database is what they consult. Arguing about where the hardware really is does not change the outcome.

For choosing a VPN server, trust latency over the reported country. A round trip under 30 milliseconds cannot have crossed an ocean, whatever any record says. The server list states what each location is; the ping is what confirms it.

For privacy reasoning, treat the city as noise and the country as probably right. Anyone building a threat model around city-level geolocation is building on something that is wrong a large fraction of the time.

Checking your own

Open what is my IP and compare the reported location with where you actually are. Then check the same address against a second vendor. Disagreement between two commercial databases about the same address is extremely common, and seeing it once is the fastest cure for treating any single answer as authoritative.

IPv6 changes the picture slowly

IPv6 blocks are allocated in far larger units, and a residential connection typically receives a whole prefix rather than a single address. In principle that makes location easier, because the prefix is stable and tied to the subscriber line rather than reassigned from a pool.

In practice the databases have less history for IPv6, fewer measurements and more gaps, so IPv6 geolocation is currently somewhat worse than IPv4 despite the underlying data being cleaner. That will invert as coverage improves.

Why vendors disagree with each other

Each builds its dataset independently, weights the inputs differently, and updates on its own schedule. One may have an ISP's cooperation in a market where another does not; one may have run measurements last week where another has data from last year.

So "which one is right" often has no answer. If a location matters — for a legal question, or because a service is applying a rule — the useful move is to check which vendor that service uses and correct the record with them, rather than to establish some abstract truth about the address.

Sources

  1. RIPE NCC — database documentation
  2. RFC 9092 — Finding the Authoritative RIR of an IP Address
  3. IANA — IPv4 address space registry

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine