Comment by manquer

5 hours ago

Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]

There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.

The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).

Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.

[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.

Don’t think there was ever a time since Netflix started streaming where they only licensed global rights to shows. For their own originals they get global rights but the majority of their content is licensed and has always been slightly different in different territories.

That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.