Free tool

Anti-Bot Detector

Find out which bot protection, WAF, CDN and CAPTCHA a website uses. Enter a URL and see what stands between you and the data - with the evidence behind every finding.

Try:

Free, no signup. We send one request to the site and report only fingerprints, never page content.

How it works

Evidence, not guesses

1

One ordinary request

We load the page once from our server and follow its redirects, the way a browser without JavaScript would.

2

Fingerprint matching

Headers, cookies, page code and DNS records are matched against the known signatures of 25 security and CDN products.

3

A clear verdict

Every finding lists the exact cookie, header or script behind it, plus whether a plain request without a browser got the page, was challenged or was blocked.

What we detect

Anti-bot systems and how to recognize them

The protections you meet most often when scraping, and the signs that give each one away.

Cloudflare

The most common edge network. Its bot protection (Bot Fight Mode, Super Bot Fight Mode, Bot Management) scores every request and answers suspicious ones with a JavaScript challenge or Turnstile.

Telltale signs

__cf_bmcf_clearancecf-raycf-mitigated/cdn-cgi/challenge-platform/
How to scrape these sites →

DataDome

Real-time bot protection used by e-commerce, classifieds and travel sites. Blocked visitors get a 403 with a slider CAPTCHA served from captcha-delivery.com.

Telltale signs

datadomex-datadomex-dd-bcaptcha-delivery.com
How to scrape these sites →

HUMAN (PerimeterX)

HUMAN Bot Defender, formerly PerimeterX. A client-side sensor collects browser signals, and visitors who fail get the "Press & Hold" challenge.

Telltale signs

_px3_pxhd_pxvidpx-captchapx-cloud.net
How to scrape these sites →

Akamai Bot Manager

Bot Manager runs on Akamai's edge. A sensor script reports browser telemetry and the _abck cookie carries the verdict; blocked requests get "Access Denied" with a reference number.

Telltale signs

_abckbm_szak_bmscAkamaiGHosterrors.edgesuite.net
How to scrape these sites →

Imperva (Incapsula)

Imperva (formerly Incapsula) combines a WAF with Advanced Bot Protection. Its challenges are served from the _Incapsula_Resource path.

Telltale signs

incap_ses_*visid_incap_*reese84x-iinfo_Incapsula_Resource

Kasada

Kasada answers unknown clients with a 429 and a proof-of-work JavaScript challenge, then expects signed x-kpsdk headers on every later request.

Telltale signs

x-kpsdk-ctx-kpsdk-cdips.jsHTTP 429

AWS WAF

Amazon's web application firewall, often with Bot Control. Challenged visitors get a 202 page that runs JavaScript and sets the aws-waf-token cookie.

Telltale signs

aws-waf-tokenx-amzn-waf-actionAwsWafIntegrationHTTP 202

F5 BIG-IP

F5 BIG-IP ASM / Advanced WAF guards many banks and enterprise sites. Rejected requests see "The requested URL was rejected" with a support ID.

Telltale signs

TS01…BIGipServer…support ID

Radware Bot Manager

Radware Bot Manager (formerly ShieldSquare) sets __uzm cookies and sends suspicious visitors to a CAPTCHA on validate.perfdrive.com.

Telltale signs

__uzma__uzmbperfdrive.com

Sucuri

A cloud WAF popular with WordPress sites. Traffic is proxied through Sucuri, which can block requests or answer them with a JavaScript check.

Telltale signs

x-sucuri-idx-sucuri-cachesucuri_cloudproxy_js

Also detected

Cloudflare TurnstileGoogle reCAPTCHAhCaptchaArkose LabsGeeTestQueue-itWordfenceReblazeVercel FirewallAmazon CloudFrontFastlyAkamai CDNAzure Front DoorVercel

FAQ

Frequently asked questions

How can I tell which anti-bot protection a website uses?

Each vendor leaves fingerprints: cookies such as __cf_bm (Cloudflare), datadome, _abck (Akamai) or _px3 (HUMAN), response headers such as cf-ray or x-datadome, and scripts loaded from the vendor's domain. This detector checks all of them in one request and shows which ones it found.

Why does the detector say "Challenged" when the site opens fine in my browser?

Protections score every request. A real browser on a home connection usually passes, while a plain request from a data center - which is what most scrapers send - gets a challenge or a block. The verdict shows what a scraper would face.

Can a site be protected even if nothing is detected?

Yes. Server-side rules, rate limits that only kick in after many requests and behavioral analysis leave no trace in a single response. "No known protection detected" means the common products are absent, not that the site will never block you.

Do you store the pages you check?

No. Only the fingerprints and evidence shown in the report are produced, and results are cached for about 10 minutes so repeated checks of the same URL are instant.

How do I scrape a site protected by Cloudflare, DataDome or Akamai?

You need a convincing browser fingerprint, clean IP addresses and a way to pass challenges when they appear. ScrapeUnblocker handles all of that in one API call: send the URL, get the rendered HTML back, and pay only for requests that succeed.

Try ScrapeUnblocker free

95%+ success rate · from 0.55€ per 1,000 calls · 500 free requests on signup.