Could a tool of transparency become a weapon of deception? Elon Musk’s X has lit a firestorm of debate with a new country-of-origin labeling feature, devised to show the geographic home of accounts. On paper, it’s a strike at misinformation networks in particular those masquerading as domestic voices while pulling their levers from abroad. In practice, experts caution that it’s a fragile system based on technical signals that are notoriously easy to manipulate.

The feature draws on multiple data points: IP addresses from internet service providers, app store region settings, historical login locations, and possibly GPS data. X reportedly pulls data from commercial geolocation databases like MaxMind, a staple in the trust-and-safety industry, in concert with user-provided information. In some cases, the system estimates a location based on the most frequent login point over a rolling 30-day window. But each of these signals carries inherent weaknesses. IP-based geolocation is thrown off by mobile carrier routing, corporate networks, or most critically VPNs and proxies. VPN software masks an IP and lets a user appear to be in virtually any country, while GPS spoofing feeds devices false coordinates through either hardware transmitters or software-based manipulation.
The vulnerability isn’t theoretical. Within hours of rollout, journalists found their profiles tagged with countries they had merely visited months earlier. Starlink’s satellite internet service itself warns that its geolocation can be “several states, provinces, or sub-regions” away from reality. X’s own disclaimer concedes that “this data may not be accurate” and notes that some ISPs use proxies automatically, without user intervention.
These flaws matter because the stakes are high. Foreign influence operations have repeatedly depended on networks of accounts masquerading as local citizens in recent election cycles. Researchers have documented pro-MAGA accounts using stolen images of European models while posting from Southeast Asia and Russian-linked troll farms seeding false narratives about election fraud through coordinated posting patterns. The new labels can help identify such actors-the “closest we get to understanding who might be behind them,” in the words of Benjamin Strick from the Centre for Information Resilience-but if the data is wrong, the tool can just as easily confer false legitimacy. A bad actor spoofing a U.S. location could be misread as a trusted domestic voice, undermining the very transparency the feature aims to provide.
Technically speaking, the detection of coordinated inauthentic behavior requires much more than one single geolocation flag. Times of posting in sync, linguistic anomalies, duplication of content across accounts, and network analysis of follower relationships are only a few of the variables analysts look for. Facebook has implemented state-controlled media labels, which studies have shown can decrease the engagement in propaganda-if users both notice and trust the labels. In a Carnegie Mellon-led study, such tags cut shares 34% and likes by 46% when applied to Russian and Chinese state media, but their impact depended a great deal on visibility and public sentiment toward the labeled country.
X’s problem is accentuated further by its weakened trust-and-safety infrastructure. Since Musk’s takeover, the company has shed much of its moderation staff, including engineers focused on influence operations. That leaves automated systems-now supplemented by AI-shouldering the burden of spotting sophisticated adversaries who can blend technical obfuscation with social engineering. VPN masking and GPS spoofing are only parts of the arsenal; influence operators also exploit platform monetization schemes, earning revenue through subscriptions and ads as they push divisive narratives.
The risk isn’t confined to misinformation. Dissidents in authoritarian states may have very real reasons for concealing their locations. Even with regional disclosure toggles, a mislabeled account could attract dangerous attention. Privacy advocates, such as Calli Schroeder, caution that single-sided changes without consultation with experts can put sensitive users at risk of unforeseen harms.
From an engineering perspective, the path to greater accuracy lies with incorporating multi-signal verification: cross-referencing IP data with device telemetry, login behavior, and anomaly detection algorithms capable of flagging improbable location shifts. It requires solid countermeasures against spoofing-things like monitoring for sudden GPS jumps inconsistent with network routing, or using triangulation with multiple receivers to validate position data. Without these, the feature’s promise of “securing the integrity of the global town square” may remain aspirational-and sometimes dangerously misleading.

