Payout Denied Over "Logins from Three Countries"? A Step-by-Step Evidence Playbook for Funded Traders on MetaTrader 5

7 October 2026, 12:19
Bruno Nunes Myrrha Ribeiro
0
39

My funded account hit every target without a single rule violation. The day I requested the payout, the compliance team wrote back: my account had been accessed from three countries in a short period, and I had to prove that I had not shared it or used it from abroad.

The numbers of that case are the whole lesson. One VPS, in one country, running one MetaTrader 5 terminal around the clock. Fifteen months of remote-session logs on that server. Three countries in the allegation. Two of the three IP addresses never appeared in a single log entry. Once the evidence was on the table, the payout was released six days later.

What decided the case was a set of files I had been keeping long before I needed them. This post is the exact procedure, so you never have to improvise it.

Why IP addresses decide payouts

Prop firms record the IP address behind every login and, in many cases, behind every order. Their rules differ: some forbid VPS and VPN connections entirely, others accept a VPS with a dedicated IP and reject shared ones, and almost all of them flag "impossible travel", meaning logins from distant countries within hours. Data-center addresses, corporate networks, mobile carriers that share one public IP among thousands of users, and security software can all look suspicious to an automated check.

Three things make an IP-based allegation hard to answer:

  • You cannot prove where you were not. A request to "explain" a location you never connected from asks for an impossible negative.
  • The record belongs to one side. You cannot audit the firm's log, only your own.
  • The address in their record is not always your machine. A MetaTrader terminal connects through access points chosen by latency, and a web dashboard login, a phone app login and a terminal login each leave their own address.

All three have the same answer. Build your own record from day one, in a form nobody can dispute.

Phase 1: Before your first trade

  1. Rent a VPS in your own name and keep the invoice. Write down its public IPv4 and IPv6 addresses and the provider's location. Check your firm's rules first: if it bans VPS use, trade from a fixed home connection instead and keep your internet provider's bills.
  2. Run the funded account in one terminal on one machine. Do not log in to that account from your phone, the web terminal, a laptop or a friend's computer. Every one of those logins writes a new address into the firm's record.
  3. Never share the master or the investor password. A shared investor password is still a login from somewhere else.
  4. Give every strategy its own magic number. Every deal stores the magic number of the program that opened it. A stable set of numbers, from one terminal, is an execution signature that answers "copy trading" and "group trading" before anyone asks.
  5. Make the Windows logs large enough to cover months. The default sizes roll over in weeks. Run once, as administrator:

wevtutil sl "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational" /ms:104857600 wevtutil sl Security /ms:209715200

Phase 2: Every week, five minutes

  1. Export the remote-session and logon logs in their native format. Events 21 and 25 record each remote session with its source address; events 4624 and 4625 record successful and failed logons.

wevtutil epl "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational" C:\Evidence\rdp_2026-10-07.evtx wevtutil epl Security C:\Evidence\security_2026-10-07.evtx

  1. Hash the files the moment you export them. A SHA-256 hash proves later that the file was not edited after that date.

Get-FileHash C:\Evidence\*.evtx -Algorithm SHA256 | Export-Csv C:\Evidence\hashes_2026-10-07.csv -NoTypeInformation

  1. Keep a one-line summary of every address that ever opened a session. This is the table you will send first:

Get-WinEvent -LogName 'Microsoft-Windows-TerminalServices-LocalSessionManager/Operational' | Where-Object { $_.Id -in 21, 25 } | ForEach-Object { ([xml]$_.ToXml()).Event.UserData.EventXML.Address } | Group-Object | Sort-Object Count -Descending | Select-Object Count, Name

  1. Save the terminal side. In MetaTrader 5, File, Open Data Folder: the logs folder holds one journal per day with every authorization of your account. Export the account history from the Toolbox (History tab, right-click, Report). Store both next to the Windows logs.

Phase 3: When the email arrives

  1. Do not send excuses or travel documents for a place you never were. Answering with a story accepts their frame. Answer with records.
  2. Ask four precise questions. Anyone with access to the log can answer them in minutes:
    • the exact date and time, in UTC, of each access they cite;
    • whether each address is the true origin of the connection or a gateway or access point in between;
    • whether each record is a login to the trading terminal or to the web dashboard;
    • the numbered clause of the terms you are said to have breached.
  3. Send a numbered index of your evidence and offer each item the same day it is requested: provider panel and invoice, the .evtx exports with their hashes, the address summary, the terminal journals and the trade history with magic numbers.
  4. Set a reasonable deadline, keep every message, and stay factual. Silence after a precise question is also an answer, and it belongs in your file.

The checklist to save

  • VPS or home line in your name, invoice saved, public IP written down
  • Funded account logged in from one terminal only; no phone, web or second PC
  • Passwords never shared, investor password included
  • One magic number per strategy
  • Windows log sizes increased on day one
  • Weekly: .evtx export, SHA-256 hashes, address summary, MT5 journals, account history
  • At a flag: four questions, numbered evidence index, deadline, archive everything

The procedure costs five minutes a week. Without it, the burden is on you to explain records you never saw. With it, every claim about your account can be checked against files dated long before anyone asked.

This is my own experience and procedure, not legal advice. Read your firm's terms on VPS, VPN and device use before you start.