What the platform can see
When a visitor connects through a consumer VPN, the destination site usually sees the public IP of the VPN exit. IP geolocation services may then map that address to a U.S. or European city. The visitor’s browser, language, time zone, network path, or purchase eligibility may tell a different story, but none of those facts should be treated as definitive in isolation.
Google’s own guidance distinguishes clicks from sessions and asks advertisers with suspicious activity to preserve campaign context, logs, GCLIDs, user agents, and trend evidence. That is the right mental model: the network location is one field in a larger event record.
Why the difference matters commercially
Software companies often target a limited sales territory, while online stores may have strict delivery, tax, or support boundaries. A click that appears to come from a supported market but repeatedly fails to engage, generates no eligible lead, or arrives in a suspicious pattern may deserve investigation. The business question is not “which nationality clicked?” It is “does the complete session look like a plausible customer or an invalid event?”
Practical rule: report the observed IP and network classification, then state the uncertainty. Do not write that a VPN proves the visitor’s physical location or intent.
What to preserve
- UTC timestamp, landing URL, campaign, ad group, keyword, and click ID.
- Observed IP/network type, ASN, apparent country, and any proxy reputation response.
- Behavioral evidence such as repeated clicks, session timing, scroll depth, and conversion outcome.
- The trend: for example, a sudden click spike without a corresponding lift in qualified conversions.
For the product workflow, see BotRefund VPN Detection and the companion guide on geo mismatch versus VPN evidence.