Modern bot detection is layered. A request is scored on several things at once, and any one of them can get it blocked:
- The IP. Its network owner (ASN), reputation and recent request volume.
- The connection. The TLS fingerprint and HTTP/2 fingerprint of the client software.
- The request. Header set and order, User-Agent, cookies.
- The browser. JavaScript challenges that read the browser fingerprint and check for automation flags.
- Behaviour. Request rate, navigation paths, mouse and timing patterns.
Why it matters when you buy proxies
A proxy changes layer one and nothing else. If a site blocks you because your HTTP client's TLS handshake looks like Python, a more expensive proxy type will not help; a client that sends browser-like fingerprints will. Work out which layer is failing before you spend money on the wrong one.
How to tell what is blocking you
Run the same request with the same client from two different proxy types. If both fail the same way, the problem is probably above the IP layer. Watch for soft blocks too: a 200 OK whose body is a CAPTCHA or challenge page counts as a failure, so check the page title or a selector you expect, not just the status code. Cloudflare errors when scraping decodes the codes one large vendor returns, and how to avoid getting blocked works through each layer.