Every guide, comparison and detector run we have published under detection.
Old headless Chrome gave itself away through a UA token, empty plugin arrays and zeroed window dimensions, and new headless mode closed most of that. What is left to detect is almost always the absence of a real GPU, not a flag.
Cloudflare scores IP reputation and TLS behaviour before your browser fingerprint is ever read, then layers a managed challenge and a behavioural score on top. Most blocks people blame on fingerprinting are actually decided one layer earlier.
WebRTC gathers ICE candidates over UDP, outside the HTTP or SOCKS proxy path, so a site can read your real public IP with two lines of JavaScript regardless of what the address bar shows. Disabling WebRTC outright trades one tell for another.
The TLS handshake and HTTP/2 frame order reveal what software made a request, regardless of the User-Agent header. JA3 and JA4 hash that order, which is why a copied Chrome header over a Python handshake fails before content loads.
Residential is not automatically better and datacenter is not automatically dead. What actually decides the outcome is whether the proxy is bound to the identity, and most setups get that part wrong in a way that is easier to detect than the IP itself.
Detection stopped asking which fonts you have and started measuring how wide they are. A missing font is not hidden: it renders in the fallback and measures exactly like a family nobody has ever installed. If your persona claims Windows on a machine that is not Windows, that is a one-line contradiction, and no amount of aged profiles or clean residential exits talks you out of it.
A high anonymity score means little. What gets profiles flagged is contradiction between signals, not any single value. A checklist of the pairs that must agree, and how to test each one in a few minutes.
DataDome, Kasada, Cloudflare and PerimeterX do not run one check, they score a risk profile from network, TLS, fingerprint, behaviour and history. Understanding which layer flagged you is the difference between fixing it and guessing.
The most common complaint in this category is that people set up a fingerprint browser and residential proxies and got banned anyway. Usually the tooling was fine. Here is what the tooling never covered, ranked by how often it is the real cause.