Logging in from a new country
Logging in from a new country
The message always arrives in the same shape. They banned me for logging in from a new country. I have read a lot of these now, usually with a screenshot of the platform’s own security page attached, and I have never once seen a platform object to a country.
What it objected to was a sequence. A session in one place, and another one somewhere the person could not possibly have reached in the time available. The country was incidental. The clock did the work.
That distinction is not pedantry. It decides which parts of a setup are cheap to move and which parts will cost you the account, and most people have those two the wrong way round.
What the check actually computes
The name for it inside these systems is impossible travel, which is unusually honest naming for the industry.
It takes two sessions on one account. For each it has a location, derived from the address, and a timestamp. Then it divides distance by elapsed time and looks at the number that falls out. If that number is faster than a body can move, one of the two sessions is lying about where it came from.
Two points, a clock, a division. That is the entire feature.
Notice what the arithmetic cannot resolve on its own. It knows one session is wrong. It has no way of knowing which. So it does not quietly discard the newer one and keep the older, it stops and asks the account to prove it is still the account, which is why these normally land as a challenge and not a removal.
The removal arrives later, out of how the challenge gets answered.
The mismatch you are worried about is the wrong one
Here is the sequence that costs people accounts, and it costs them precisely because the reasoning sounds right.
You notice the account is registered as living in one country while your exit sits in another. The inconsistency bothers you. So you deal with it. Open the tool, switch the exit to the country the account claims, carry on with the afternoon.
Now read your own session list the way a reviewer reads it. Activity from the old address at ten past two. Activity from an address on another continent at fourteen minutes past. Four minutes, several thousand kilometres, one login.
The state you were unhappy about was static. Static geographic mismatch is a weak signal and platforms tolerate it all day, because a large number of genuine users hold an account registered in a country they no longer live in.
What you replaced it with was motion, and motion at an impossible speed is the specific thing this check exists to find. You took a signal the system barely weighs and converted it into the one it was built for.
So the operator who leaves the mismatch alone is usually fine, and the operator who tidies it up between two clicks gets stopped. That is why this keeps happening to careful people rather than sloppy ones.
What a genuine trip looks like from the other side
The legitimate case is worth reading closely, because it is the thing you are trying to resemble.
Somebody gets on a plane. From the platform’s side, this is what appears in the record.
A session in the origin that ends. Then several hours where the account does nothing at all, which is what a taxi and an airport and a flight look like when all you have is a log. Then a session in the destination, from the same machine the platform has seen for months, with the same browser build and the same stored cookies, doing something small and unremarkable.
Three properties, none of them clever. A gap long enough for the arithmetic. A device that did not change. Ordinary behaviour on arrival.
Almost all real travel has all three, which is why almost all real travel passes.
The third one gets underweighted. A traveller opens the account and does something trivial with it, because that is what people do in a hotel room. An account that lands in a new city and immediately performs the largest action it has ever performed is telling a different story from one that lands and reads a page. Same gap, same device, same distance, different conclusion at the far end.
The gap is the only variable you control
Of the three, the gap does the most work, and it is the only part of the equation you can actually move.
Distance is fixed by geography. Time is not. An hour between two sessions on different continents produces a number no person can produce. Six hours produces a number that is merely a flight.
Which means the rule has nothing to do with addresses at all. Let the session end. Leave the account completely alone. Come back later.
And end it properly. Closing a laptop lid does not end a session. The session is a live object on their side with your address attached to it, and if it never ends, the gap you were counting on never begins.
The device is what stops a check becoming a lock
The second property carries more weight than people give it credit for.
When location changes and hardware stays identical, a reviewer has an anchor. Same machine, same browser, same fonts, same stored session. It can tell itself a one line story: this is the same person, somewhere else. That story is cheap to believe and it resolves the check.
When location changes and the device is unfamiliar too, the anchor is gone. Two of the things it knew about the account changed in one step, and the simple explanation is no longer available. So it escalates.
That is the mechanism behind the rule I give everybody. Change one thing at a time.
If the exit is moving this week, the hardware stays exactly as it is. If the account is moving onto a new machine, it keeps appearing from the address it has always appeared from while that happens. Days between the two changes, not hours.
One novelty gets you a prompt, and a prompt is answerable. Two gets you a review, and reviews resolve badly far more often than prompts do.
The order is not arbitrary
Do the device first, from the familiar location, and let the account run there normally for a while. Move the location afterwards, from the machine that is by then familiar.
Reversed, you are asking a system that has just watched an account appear somewhere new to also accept hardware it has never seen. Spreading that across two weeks is still enormously better than doing both on a Tuesday afternoon. The sequence still reads worse than it needs to, and there is no reason to pay for that.
Two other layers sit underneath all of this and neither is what fires the check. The address you appear from carries a reputation of its own, which makes every check stricter when it is bad. And the timezone and language your browser reports have to agree with the address, or the account contradicts itself before the travel arithmetic runs at all. Both worth fixing. Neither is this.
If it has already fired
Briefly, because the aftermath deserves its own treatment.
Stop signing in. Every extra session created while somebody is looking at the account is one more point for the division to work with.
Go back to the address and the device from before the jump, the pair the platform already knows, and answer the challenge from there.
The thing never to do is answer it from the new location. That repeats the exact sequence that triggered the check, during the one window when a system is guaranteed to be reading closely.
Once it clears, leave the location alone for several days.
Why everyone asks about countries anyway
I get asked which countries are safe. Somebody once sent me a colour coded spreadsheet ranking countries by supposed risk, and he had clearly put real hours into building it.
It is the wrong question, and it produces exactly the wrong behaviour. A person who believes the country is the risk will choose the country with enormous care and then change it at whatever moment happens to be convenient. That is backwards. The choice is nearly free. The timing is the expensive part.
The country is the least interesting variable in this whole problem and it is the only one anybody wants to discuss, because a list of safe countries feels like knowledge and a rule about waiting six hours feels like a chore.
What I cannot tell you
I do not know the thresholds and nobody outside these companies does. How many hours a given platform wants for a given distance. Whether a hop between two business cities is weighted differently from a first appearance in a region. Whether this is a hard rule or one input into a score with six other inputs. None of it is published, and anybody handing you a safe number of hours has invented it.
My evidence is lopsided too, and worth discounting for that. What I have is a few hundred lines running under other people’s fleets and the messages that arrive when something goes wrong on one of them. Those messages skew hard toward accounts that moved fast, or moved twice at once. An account that moved slowly and got flagged anyway had no particular reason to write to me about it.
Guides and the stack we run and test are at Multi Account Ops.
Get new guides and videos first — join the Telegram channel.