Which Top Sites Block Datacenter IPs — September 2026

We ask the top 1,000 sites for their homepage twice at the same moment — once from a datacenter IP, once from a residential one — and publish only the cases where the two answers differ. Of 709 sites that gave us a clean answer, 52 (7%) refused the datacenter request and served the residential one.

52block datacenter IPs
7%of sites we could measure
54%of blockers are Cloudflare-fronted
291excluded, no clean answer
The headline

A datacenter IP is refused by 7% of the sites we could measure

This is the number that decides whether a scraper works. The same request, sent in the same second from a residential IP, went through on every one of those 52 hosts — so the refusal is about where the request came from, not what it asked for. The reverse happens too, and far less often: 17 sites refused the residential request while serving the datacenter one.

By popularity

Bigger sites block harder

Top 1007% · 5 of 73
101–5005% · 14 of 271
501–1,0009% · 33 of 365
Who does the blocking

The edge in front of the refusal

cloudflare28
undisclosed12
fastly6
akamai4
cloudfront2

“Undisclosed” means the host announced no CDN in its response headers — not that it has none.

The list

Top sites refusing datacenter IPs

RankSiteFrom datacenterFrom residentialEdge
35fastly.net403200fastly
46digicert.com403200fastly
75chatgpt.com403200cloudflare
86openai.com403200cloudflare
94samsung.comno response200akamai
105reddit.com403200
148intuit.com429200akamai
192rubiconproject.com403200cloudflare
196vungle.com403200cloudflare
217mit.edu403200
238canva.com403200cloudflare
242duckdns.orgno response200
273forter.com403200cloudflare
282weibo.comno response200
309wiley.com403200cloudflare
334ailawandorder.comno response200
391att.com403200akamai
491quora.com403200cloudflare
494markmonitor.com403200cloudflare
505mediatek.comno response200cloudflare
512behance.net403200fastly
543patreon.com403200cloudflare
545oup.com403200cloudflare
562deviantart.com403200cloudfront
567tripadvisor.com403200cloudfront
576teamviewer.com403200cloudflare
584berkeley.edu403200cloudflare
606wix.comno response200fastly
621ikea.com403200cloudflare
636branch.io403200cloudflare
656imgur.com429200fastly
658elpais.com403200
735mlb.com403200fastly
745abovedomains.comno response200
750mediafire.com403200cloudflare
801people.com403200cloudflare
803att.net403200
817no-ip.comno response200
832liftoff.io403200cloudflare
860pexels.com403200cloudflare
899kleinanzeigen.de403200akamai
902coupang.com403200
911youku.comno response200
920genius.com403200cloudflare
930odoo.com403200
933investopedia.com403200cloudflare
940character.ai403200cloudflare
942chaturbate.com403200cloudflare
944auvik.com403200cloudflare
967ancestry.com403200cloudflare

The full set is a free API: GET https://proxmint.com/api/site-blocks — add ?format=csv for a spreadsheet, ?blocked=all for every measured host. No key, CORS open, published CC BY 4.0.

Methodology

How we measure this

  1. Take the list. The Tranco daily top 1,000, re-fetched every run so the sample is reproducible.
  2. Ask twice, at the same moment. A plain GET / from our own datacenter IP and the same request through a residential exit, following up to three redirects. Status and headers only — never the page body.
  3. Confirm before counting. A refusal is re-asked before it counts: twice from the datacenter, where the IP never changes, and up to three times residentially, where every attempt draws a different exit.
  4. Publish only the difference. A site counts as blocking datacenter IPs when the datacenter request was refused — 403, 429, a Cloudflare challenge, or no answer at all — and the residential request genuinely succeeded.
  5. Exclude what we could not measure. 291 hosts where one leg never heard back from the origin at all. Most are infrastructure domains that Tranco ranks by DNS traffic and that serve no homepage to anyone — akamai.net, gtld-servers.net. A site that refuses both vantage points is not excluded: that is a measurement, and its answer is that it does not single out datacenter traffic.

On the user-agent: we identify ourselves honestly rather than impersonating a browser. We checked what that costs — across the top hosts, a browser user-agent and realistic Accept headers changed no status on either leg. The refusals we record are about the IP, not about how we introduce ourselves.

Data as of Sep 2, 2026, 11:02 PM UTC. · Companion measurement: how reliable free proxies actually are

Working from the wrong kind of IP?

fastly.net, digicert.com and chatgpt.com all refused our datacenter request and served the identical one from a residential IP. Same second, same headers, different answer.