Detection run, August 2026 - one of the four checks blocked us
This is the first of a monthly series. The point of publishing it is that it is dated and repeatable, not that it is flattering. One of the four checks blocked us, and that is in the table with the rest.
Conditions
| Run started | 2026-08-02 00:18 UTC |
| Run finished | 2026-08-02 00:21 UTC |
| Kernel | Chrome 150 |
| Profile | freshly created, default settings, nothing tuned |
| Proxy | managed residential, exit 149.52.102.108, Houston US |
| Host | macOS, headful |
The profile was created and used once. No warming, no history, no per-site tuning. That is deliberately the weakest realistic case.
What the profile presented
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/150.0.0.0
platform Win32
languages en-US, en
timezone America/Chicago
webdriver false
hardware 8 cores, 16 GB, 1536x864
WebGL vendor Google Inc. (Intel)
WebGL render ANGLE (Intel, Intel(R) UHD Graphics 620 Direct3D11 vs_5_0 ps_5_0, D3D11-27.20.100.9316)
The proxy exits in Houston and the browser reported America/Chicago. That binding is automatic, and it is the single most common thing to get wrong by hand.
Results
| Check | Result | Detail |
|---|---|---|
| whoer.net | Pass | Disguise 100%. Proxy: No. Anonymizer: No. Blacklist: No. OS read as Win10.0, browser as Chrome 150.0 |
| CreepJS | Inconclusive | Page loaded (HTTP 200) and produced a fingerprint ID, but our harness failed to read its score fields. Our fault, not a result |
| DataDome (leboncoin.fr) | Blocked | HTTP 403, CAPTCHA challenge served, 1,206-byte body. No listings reached |
| Kasada (footlocker.com) | Pass | HTTP 200, real storefront rendered, 1.59 MB body, no interstitial |
About the DataDome failure
Read that row again, because it is the interesting one.
leboncoin.fr returned 403 with a CAPTCHA. The profile did not get through. A previous capture of this same target, taken weeks earlier and still shown on our homepage at the time of writing, showed it passing. Today it does not.
We are not going to explain that away. Some honest observations about what it does and does not mean:
- A single run is a single data point. Same profile, same proxy, an hour later, could differ. That is what makes a permanent "undetectable" badge dishonest, in either direction.
- The proxy is the most likely factor. This exit is a shared residential address. DataDome scores IP reputation heavily, and we did not check this address's history before the run. A burned exit fails before the fingerprint is ever evaluated.
- A brand-new profile with zero history is the weakest case. Real usage carries accumulated cookies and behaviour that a first-visit profile does not have.
- It might simply be that their detection improved. That happens, and pretending otherwise would make every future report worthless.
What we can say is narrower and more useful: the fingerprint layer looked coherent (whoer 100%, proxy undetected, no automation tells), and one commercial wall let it through while another did not.
The CreepJS gap
CreepJS loaded and returned a fingerprint ID, so the browser reached it. Our extraction script failed to pull the score fields out of the rendered page, so we have no numbers to publish and we are not going to estimate them. Harness bug, being fixed for the September run.
Method, so you can repeat it
- Create a profile in the desktop app or via
openProfile(). Change nothing. - Bind a residential proxy. Timezone, locale and geolocation follow the exit IP automatically.
- Open, in one session: whoer.net, abrahamjuliot.github.io/creepjs, leboncoin.fr, footlocker.com.
- Record HTTP status and the on-page result for each.
Every target is public and none of them require our cooperation. The free tier is unlimited local profiles with no card, so running this yourself costs an afternoon.
If your result differs from ours, ours is the one to distrust: we ran one profile through one proxy from one machine.
What we changed because of this run
Our homepage still carries a DataDome screenshot from an earlier capture showing a pass. Today's run contradicts it. That screenshot is being replaced with a link to this page, because a static image of a good day is exactly the kind of claim this series exists to stop making.
Next run: 2026-09-01. Same method, same four checks, CreepJS extraction fixed.
See what a profile actually is or check yours against the same list.
Try it on the free tier.
Unlimited local profiles, no credit card. Check it against the detectors yourself.