Which Top Sites Block Datacenter IPs — September 2026

We take the top 1,000 names in the Tranco list. 772 of them serve a homepage — the rest are infrastructure hostnames with no address of their own to answer from. Each one that does, we ask for its homepage twice at the same moment — once from a datacenter IP, once from a residential one — and publish only the cases where the two answers differ. Of 698 sites that gave us a clean answer, 31 (4%) refused the datacenter request and served the residential one.

31block datacenter IPs
4%of sites we could measure
42%of blockers are Cloudflare-fronted
74asked, no clear answer
Check your own

Does the site you need block datacenter IPs?

One homepage request from our datacenter IP and one through a residential exit, at the same moment. We read the response headers — status, type and size — and never the page body. A domain, not a full URL. 6 checks per 10 minutes.

The headline

A datacenter IP is refused by 4% of the sites we could measure

This is the number that decides whether a scraper works. The same request, sent in the same second from a residential IP, went through on every one of those 31 hosts — so the refusal is about where the request came from, not what it asked for. The reverse happens too, and far less often: 17 sites refused the residential request while serving the datacenter one.

By popularity

Rank barely changes the odds

Top 1004% · 3 of 74
101–5003% · 7 of 263
501–1,0006% · 21 of 361
Who does the blocking

The edge in front of the refusal

cloudflare13
undisclosed8
fastly5
cloudfront3
akamai2

“Undisclosed” means the host announced no CDN in its response headers — not that it has none.

The list

Top sites refusing datacenter IPs

RankSiteFrom datacenterFrom residentialEdge
36fastly.net403200fastly
47digicert.com403200fastly
85openai.com403200cloudflare
193medium.com403200cloudflare
208duckdns.orgno response200
220mit.edu403200
298weibo.comno response200
316wiley.com403200cloudflare
405espn.com202200cloudfront
451bluehost.com403200cloudflare
511behance.net403200fastly
559patreon.com403200cloudflare
567deviantart.com403200cloudfront
575tripadvisor.com403200cloudfront
580teamviewer.com403200cloudflare
590att.com403200akamai
630ikea.com403200cloudflare
639tencent.comno response200
664elpais.com403200
673imgur.com429200fastly
734mlb.com403200fastly
766mediafire.com403200cloudflare
838odoo.com403200
844att.net403200
855meta.com429200
907kleinanzeigen.de403200akamai
934genius.com403200cloudflare
948character.ai403200cloudflare
951chaturbate.com403200cloudflare
958investopedia.com403200cloudflare
969ancestry.com403200cloudflare

The full set is a free API: GET https://proxmint.com/api/site-blocks — add ?format=csv for a spreadsheet, ?blocked=all for every measured host. No key, CORS open, published CC BY 4.0.

What the list contains

Why the top 1,000 is not 1,000 websites

Tranco ranks by DNS query volume, not by visitors. A CDN hostname or a nameserver domain answers billions of lookups and serves no homepage to anybody, so it places high on a list of “top websites” without being one. 228 of the top 1,000 names — 23% — have no address at their apex to answer a request at all. We resolve every name before measuring it, and dial none of these.

RankNameWhy we did not ask it
8akamai.netno address at its apex
14ezviz7.comno address at its apex
20domaincontrol.comanswers with a private address
23akamaiedge.netno address at its apex
24hicloudcam.comno address at its apex
26akadns.netno address at its apex
27gtld-servers.netno address at its apex
33apple-dns.netno address at its apex
38aaplimg.comno address at its apex
39microsoftonline.comno address at its apex
40office.netno address at its apex
42trafficmanager.netno address at its apex

Not a tail effect: the highest-ranked of them is number 8, and the share barely moves the whole way down the list. It is also why our denominator is 772 rather than 1,000, which is not a cosmetic difference. A name with no address of its own can still draw an answer from a residential exit whose resolver replies regardless, and that answer reads exactly like “the datacenter request was refused and the residential one succeeded”. Before we resolved names first, that alone put 42 sites on this list that did not belong on it. Every row is in the API with its reason, so the count is checkable rather than merely stated.

Methodology

How we measure this

  1. Take the list. The Tranco daily top 1,000, re-fetched every run so the sample is reproducible. Tranco ranks by DNS traffic, so we resolve each name first and measure nothing that has no address to answer from.
  2. Ask twice, at the same moment. A plain GET / from our own datacenter IP and the same request through a residential exit, following up to three redirects. Status and headers only — never the page body.
  3. Confirm before counting. A refusal is re-asked before it counts: twice from the datacenter, where the IP never changes, and up to three times residentially, where every attempt draws a different exit. The residential success is the other half of the finding, so a pair that would be published is measured again from a fresh exit — a difference we cannot reproduce is not published.
  4. Publish only the difference. A site counts as blocking datacenter IPs when the datacenter request was refused — 403, 429, a Cloudflare challenge, or no answer at all — and the residential request genuinely succeeded.
  5. Exclude what we could not measure. Two different exclusions, counted apart because they are not the same claim. 228 names were never dialled: they have no apex address, being the infrastructure domains Tranco ranks by DNS traffic — akamai.net, gtld-servers.net — which serve no homepage to anyone. The other 74 we did dial, and one leg never heard back from the origin. A site that refuses both vantage points is not excluded: that is a measurement, and its answer is that it does not single out datacenter traffic.

On the user-agent: we identify ourselves honestly rather than impersonating a browser. We checked what that costs — across the top hosts, a browser user-agent and realistic Accept headers changed no status on either leg. The refusals we record are about the IP, not about how we introduce ourselves.

Data as of Sep 11, 2026, 7:36 AM UTC. · Companion measurement: how reliable free proxies actually are

Working from the wrong kind of IP?

fastly.net, digicert.com and openai.com all refused our datacenter request and served the identical one from a residential IP. Same second, same headers, different answer.