Enter to payments ·

Try2Check

— Independent · Daily —

Geo-fenced at the border, logged in 9 miles away

How iGaming geo-compliance layers IP, GPS, and risk appetite to draw invisible borders that rarely agree with each other

Geo-fenced at the border, logged in 9 miles away
Geo-fenced at the border, logged in 9 miles away

A player sitting in a hotel room in Slough, nine miles from the nearest legal UK casino floor, can open a licensed sportsbook on their phone and place a bet in under ninety seconds. The same person crossing into a jurisdiction where that operator holds no licence gets a block screen instead. The line between "allowed" and "not allowed" is not a border you can see. It is drawn by an IP address, a GPS coordinate, and a compliance team's risk appetite, and those three things rarely agree with each other.

How the fence actually gets built

Geo-compliance in iGaming runs on layers, and each layer has a different failure mode.

IP geolocation is the crude first pass. Databases like MaxMind or IPinfo map address ranges to countries, but the mapping is approximate and stale. A mobile carrier routing traffic through a Frankfurt data centre can make a Manchester user look German for a few seconds. VPNs exploit this, which is why most operators flag known VPN exit nodes and datacentre IP ranges rather than trusting the country code alone.

Device GPS is the second layer, and it only exists inside apps. A native iOS or Android app can request precise location permission and refuse to function without it. That is why regulated operators push users toward apps in markets where the rules are strict — the browser cannot be trusted the same way.

Wi-Fi and cell-tower triangulation fills gaps where GPS is weak, indoors especially. Accuracy drops to a few hundred metres, sometimes worse. Near a land border, a few hundred metres is the whole problem.

Manual review catches what the automated stack flags as ambiguous. A compliance analyst looks at the IP, the device fingerprint, the account history, and decides. A 2023 audit of one European operator's logs found that roughly 4% of sessions triggered a location review, and about a fifth of those were false positives — legitimate users in the right country, blocked anyway.

Why nine miles matters

Borders are not lines in geolocation databases. They are polygons, and the polygons are generous. An operator licensed in one US state but not its neighbour will often block a buffer zone around the state line rather than risk a violation. That buffer can be five miles. It can be twenty. The player nine miles inside the licensed state, in a town whose cell towers lean toward the unlicensed side, gets the block screen.

The reverse happens too, and it is the one regulators care about. A player physically in a prohibited jurisdiction, close enough to the border that their IP resolves to the permitted side, places bets they are not legally allowed to place. The operator's logs say everything is fine. The regulator disagrees.

The numbers behind the block

The UK Gambling Commission's licence conditions require operators to verify that a customer is physically located in Great Britain at the point of a transaction, not just at signup. That is a per-bet check, not a one-time gate. The 2005 Gambling Act's extraterritorial reach was tightened further by the Gambling (Licensing and Advertising) Act 2014, which made it an offence to advertise unlicensed gambling to UK consumers. The practical effect: an operator without a UK licence cannot legally take a bet from someone standing in Dover, even if the operator is licensed in Malta and the servers are in Ireland.

In the US, the picture is a patchwork. As of early 2024, thirty-eight states plus DC had legalised some form of sports betting, but only a subset permit online casino. A player in a state with retail-only betting who opens a casino app licensed in a neighbouring state is committing an offence in their own state, and the operator is on the hook for failing to detect it. The American Gaming Association has estimated the illegal offshore market at over $500 billion in annual handle, which gives you a sense of how many people are not being blocked.

The VPN arms race

VPN use among iGaming customers is not fringe. Surveys of online gamblers in restricted markets routinely put VPN usage above 20% for players who want access to markets their local regulator has not licensed. Operators respond by blocking known VPN ranges, checking for IP and timezone mismatches, and flagging accounts that log in from three countries in a week.

The arms race has a cost. False positives push legitimate customers toward unlicensed sites that do not bother with location checks at all. The stricter the fence, the more attractive the gap beside it.

What the fence cannot do

Geolocation is a proxy for physical presence, and proxies fail. A determined user with a residential proxy in the right country and a spoofed GPS app can defeat most automated checks. The compliance stack catches the lazy and the unlucky, not the motivated.

Regulators know this. The shift in recent years has been away from treating geolocation as a security control and toward treating it as an evidence trail. The question is no longer "did the player get in?" but "can the operator show, after the fact, that it made a reasonable effort to keep them out?" That is a lower bar, and it changes what operators build. A block screen that logs the attempt is worth more in a regulatory review than a block screen that works perfectly but records nothing.

For players, the practical upshot is uneven. Someone in a densely populated area far from any border rarely sees a block. Someone in a border town, or on a mobile network with odd routing, sees them constantly. The fence is not a wall. It is a filter with a known error rate, and the error rate is highest exactly where the stakes are highest.

The question nobody wants to answer

If a player is physically in a jurisdiction where the bet is illegal, but every automated check says they are somewhere else, who has committed the offence? The player, clearly, under most statutes. The operator, arguably, for not trying hard enough. The geolocation vendor, whose database put the border in the wrong place?

No regulator has drawn that line cleanly, and until one does, the fence will keep working about as well as it does now — which is to say, well enough to catch the people who are not trying to get around it, and not much else. The nine-mile gap between the block screen and the login is not a bug. It is the space where the entire compliance model quietly admits it is guessing.