ProxyWing

How to Bypass DataDome: Detection Layers, Working Methods, and Honest Limits

If you’re reading this guide, there’s a high chance you’ve encountered the infamous 403 error or a CAPTCHA wall when trying to scrape data from your targets. DataDome is one of the popular solutions that most websites and web apps use to block bots and other forms of malicious traffic.

Published: October 6, 2026
Reading time: 17 min

Bypassing DataDome and similar platforms like Cloudflare isn’t straightforward. These systems rely on multiple signals to determine what traffic gets through to the targets they protect, so getting past them takes just as much effort. You’ll need to implement up to four layers of solutions to bypass DataDome successfully.

In this guide, we walk through the tried and tested methods you can use to get past DataDome blocks. Let’s get into it.

Key takeaways

  • DataDome checks every request across four layers, including the IP reputation, TLS/HTTP fingerprint, JavaScript device signals, and behavior over the session before letting it in.
  • A residential IP alone is not enough to bypass DataDome: your TLS fingerprint is evaluated before the proxy is even weighed.
  • The DataDome cookie is automatically associated with the IP and fingerprint that earned it. Using it with another IP will get your traffic blocked.
  • Vanilla Playwright and Puppeteer are detected reliably. Camoufox, nodriver, and SeleniumBase CDP mode are the current baseline.
  • Models are trained per customer. That means a setup that clears site A can fail on site B the same hour.
  • Nothing here is permanent: the tag updates continuously, and every DIY bypass carries a maintenance cost that you need to consider before deploying it.

What is DataDome?

DataDome is a bot management and online fraud protection platform that sits in front of websites, web apps, mobile apps, and APIs. It acts as a server-side module, CDN worker, or reverse-proxy that protects web resources from malicious traffic. It works by scoring every request with machine learning models and returns one of three outcomes: pass, challenge, or block.

DataDome request lifecycle: TLS, IP, HTTP fingerprint, JS tag and per-customer ML feed a trust score that passes, challenges or blocks

Unlike web application firewalls that primarily match requests using static rules, DataDome asks whether the client behaves like a real browser driven by a real person. That makes it a more complex system to bypass.

DataDome company fact box

Field Details
Founded 2015 (in Paris)
Founders Benjamin Fabre (CEO), Fabien Grenier (Chairman)
Headquarters New York, Paris, and Singapore
Ownership Private, venture-backed, not acquired
Funding $35M Series B (May 2021), $42M Series C (March 2023, led by InfraVia Growth with Elephant and ISAI), ~$81–82M total raised
Core products Bot Protect, Account Protect, Ad Protect, Page Protect, Device Check
Scale (vendor-reported) 5+ trillion signals analyzed daily, decisions in under 2 milliseconds
Recognition Leader, Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026

Who owns DataDome?

DataDome is independently owned and has not been acquired. The platform’s co-founder Benjamin Fabre still serves as CEO and InfraVia Growth, Elephant, and ISAI are among its largest investors. To clear up a common confusion: it is not owned by Akamai, Cloudflare, or HUMAN. Those are actually competitors and not brands that own it.

What sites use DataDome?

Ticketing, sneaker and limited-drop retail, classifieds, travel fare pages, real estate listings, and e-commerce with volatile pricing are some of the common websites protected by DataDome. If you confirm that the site you’re targeting is also protected by DataDome, this guide will help you learn how to bypass it.

DataDome pricing and support (for site owners)

DataDome offers several plans: Essentials from $3,830/month, Advanced from $8,670/month, Premium from $10,160/month, and Enterprise starting at $13,270/month. The final cost will vary based on volume. An AWS Marketplace listing for DataDome is also available. Users can choose from any of these plans based on the level protection they need and the scale of their web resources.

How does DataDome work?

On websites that use DataDome, every request gets scored before it’s allowed through. DataDome checks the connection type, IP, headers, and (if JavaScript runs) the user’s device and behavior. It then feeds this data into a trust model trained on that specific site’s traffic, and decides in milliseconds whether to let the user through, challenge, or block them.

What DataDome inspects, layer by layer

Layer What’s checked Bot tell How to pass
IP IP type, history, location match Datacenter IP, one IP across many sessions Sticky residential/mobile IP
TLS Handshake fingerprint Fingerprint no real browser has Browser-mimicking TLS tool
Headers Order, casing, content Alphabetized or mismatched headers Browser-accurate headers
Browser (JS) Canvas, fonts, browser properties navigator.webdriver, fake renderer Hardened browser
Behavior Mouse, scroll, typing, pacing Instant clicks, no scroll, rapid-fire requests Human-like pacing
Session Cookie/IP/fingerprint consistency Same cookie, different IP Keep identity consistent

IP reputation and network signals

DataDome tracks IP history across all the websites it protects. That means a “residential” IP address that’s been overused elsewhere can score worse than a clean datacenter one. Mismatched signals hurt too. For example, a Texas IP set to Russian language and a Moscow timezone is an instant red flag and can easily get blocked.

Clean, well-managed IPs matter more than the label, which is why testing ProxyWing’s residential and mobile pools against your own target is worth the effort.

TLS and HTTP fingerprinting (JA3 / JA4)

Every connection leaves a fingerprint before any data is even sent, and standard Python HTTP libraries produce one that no real browser has. It gets checked before your IP or User-Agent even matters. This simply means changing your User-Agent alone won’t help: you’d be claiming to be Chrome while your connection says otherwise.

The code below compares the TLS fingerprint of a plain Python requests call against a curl_cffi call impersonating Chrome.

import requests
from curl_cffi import requests as cffi
CHECKER = "https://tls.peet.ws/api/all"
plain = requests.get(CHECKER).json()
print("requests JA3:", plain["tls"]["ja3_hash"])
# e.g. cd08e31494f9531f560d64c695473da9 -- a hash no browser emits
spoofed = cffi.get(CHECKER, impersonate="chrome131").json()
print("curl_cffi JA3:", spoofed["tls"]["ja3_hash"])
# matches a genuine Chrome 131 handshake

The JavaScript tag and device fingerprinting

DataDome loads a small script on the page that collects device signals and sends them back to verify the visitor. It doesn’t just read values like navigator.webdriver, it also checks whether those values have been faked, since a patched browser leaves telltale signs a real one never would. Traffic is blocked if any inconsistencies are detected.

Behavioral analysis

DataDome also tracks how you move through a site (mouse movement, scrolling, typing rhythm, and timing) across your whole session, not just one request. Adding random delays doesn’t fool it, since real human pauses aren’t random in the way a script’s are.

Per-customer machine learning models

Each protected site trains its own model on its own traffic, so there’s no single system to beat. It is common to find out that a setup that works on one site gets blocked on another within the hour. That is why general principles carry over between targets but exact configurations don’t. You need to optimize the solution differently for different targets.

What is DataDome Device Check (device intelligence)?

Device Check is an invisible version of the CAPTCHA that is designed to verify your device in the background with no puzzle to solve. That’s why scrapers can hit 403s or silent stalls without ever seeing a challenge screen, and it works on mobile apps too, not just browsers. This layer of protection adds another challenge when trying to bypass DataDome.

How to tell if a site is protected by DataDome

Do these three quick checks:

  • Network tab: reload the page and look for a request to js.datadome.co/tags.js.
  • Cookies: check for one named datadome on the site.
  • Blocked response: seeing a 403 with a link to captcha-delivery.com in the body confirms it.

The screenshot below confirms DataDome is active on the page: `tags.js` loads in the Network tab, and the `datadome` cookie is set and visible in Storage.

Browser DevTools showing DataDome tags.js in the Network tab and the datadome cookie in Storage

What a DataDome block actually looks like

There are three outcomes to watch for:

  • A silent 403 with no visible page means a hard block
  • An interstitial page asking you to enable JavaScript
  • A CAPTCHA, which is actually the best case: it means your score is low but not hopeless.

What is the DataDome CAPTCHA, and can you solve it?

It’s DataDome’s own slider puzzle, not a standard reCAPTCHA or hCaptcha. You may pay a solving service or attempt it with human-like mouse movement, but neither fixes the real issue. Remember, a well-trusted session is never shown a CAPTCHA in the first place. If you’re hitting it often, the fix is your IP and fingerprint setup, and not using a better solver. Fix those basics first.

How to bypass DataDome: what actually works

There’s no single trick to bypass DataDome since it scores every layer. Fixing just one (like your IP) while leaving another broken won’t resolve the issue. Work through the layers below in order, testing after each fix, since earlier layers are cheaper to fix than later ones.

Layer 1 — get the IP profile right

Don’t rotate your IP on every request. The datadome cookie is tied to the IP that earned it, so swapping mid-session breaks things. Instead, keep one IP for the whole session. If you’re to rotate, ensure to rotate everything together (IP, fingerprint, and cookie) as a full identity change.

Proxy types against DataDome

Here is how the different proxy types compare when used to bypass DataDome

Proxy type How it tends to score Best for Starting price
Datacenter Lowest trust, easy to spot as a shared, non-residential IP Low-value or unprotected pages, quick checks $0.87
ISP (static residential) Looks residential but stable, good until the IP gets flagged Long sessions needing one stable identity $1.71
Rotating residential Solid default, but only as good as the pool’s cleanliness Most DataDome-protected targets $1.00
Mobile (4G/5G) Highest trust: shared by many real users, costly for sites to block Toughest targets, account-based tasks $4.00

ProxyWing runs residential and mobile pools (the two categories that matter most here) across 190+ countries.

Layer 2: match the TLS and HTTP fingerprint

Use a tool like curl_cffi that mimics a real browser’s connection. Just make sure the version you claim (like Chrome 131) matches the version it’s actually mimicking. The script below sends a request through a proxy while mimicking a real Chrome browser’s TLS fingerprint, then checks whether the response was blocked with a CAPTCHA challenge.

from curl_cffi import requests
UA = ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 "
      "(KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
proxies = {"https": "http://USER:PASS@proxy.proxywing.com:PORT"}
r = requests.get(
    "https://target.example.com/listing",
    impersonate="chrome131",        # must match the UA version above
    headers={"User-Agent": UA},
    proxies=proxies,
    timeout=30,
)
print(r.status_code)
if "captcha-delivery" in r.text:
    print("Challenged -- this endpoint needs a JS-issued cookie.")

Note: This approach works for pages that don’t load the JavaScript tag. Pages that require a valid datadome cookie need a real browser too.

Layer 3: use a hardened browser, not vanilla Playwright

Standard Playwright and Puppeteer get caught easily since they leave automation traces, report a fake graphics renderer, and have a thin font list compared to a real computer. Stealth plugins can patch some of this, but they still fall behind as DataDome updates, so they tend to stop working after a few weeks.

Tooling against DataDome

Tool What it is TLS JS fingerprint Effort Note
requests / httpx Basic HTTP client Fails — Minimal Blocked instantly on protected sites
curl_cffi HTTP client, mimics browser TLS Good — Low Fine if no JS tag is served
Playwright / Puppeteer (plain) Real browser Good Fails Low Automation traces give it away
Stealth plugins Browser + patches Good Partial Medium Falls behind as DataDome updates
SeleniumBase (UC/CDP) Browser Good Good Medium Solid, actively maintained pick
nodriver Browser, no CDP traces Good Good Medium Modern successor to undetected-chromedriver
Camoufox Modified Firefox Good Strongest Higher Hardest to detect, heaviest to run
Managed scraping API Outsourced service Handled Handled Lowest Costs per request, less control

The script below launches a hardened Chrome instance through a proxy, warms up the session on the homepage before hitting the target page, and checks whether the response came back clean or challenged.

import asyncio
import nodriver as uc
PROXY = "proxy.proxywing.com:PORT"   # unauthenticated proxy, or IP-whitelisted
async def main():
    browser = await uc.start(
        browser_args=[f"--proxy-server=http://{PROXY}"],
        headless=False,               # headful avoids the SwiftShader tell
    )
    try:
        page = await browser.get("https://target.example.com/")
        await page.sleep(3)           # let tags.js run and issue the cookie
        await page.scroll_down(250)
        await page.sleep(2)
        page = await browser.get("https://target.example.com/listing")
        html = await page.get_content()
        print("blocked" if "captcha-delivery" in html else "ok", len(html))
    except Exception as e:
        print("session failed:", e)
    finally:
        browser.stop()
uc.loop().run_until_complete(main())   # nodriver docs recommend this over asyncio.run

Layer 4: behave like a session, not a request

When accessing your target, visit the homepage first, let the tag load and set the cookie, scroll around, then head to your target page with natural pauses. Remember to keep your IP, fingerprint, and cookie together as one identity throughout the session.

Layer 5: know when to stop optimizing

DataDome updates constantly, so your setup should not be created once and not updated. At low volume, a managed API is usually cheaper than your time, while at high volume running your own stack wins. Choosing between the two depends on your targets and costs.

Which scraping APIs can bypass DataDome?

Services like ScrapFly, ScrapingBee, ScraperAPI, Zyte, Bright Data, and Oxylabs handle all the technical layers for you. Test them against your real target during a trial because advertised success rates are usually higher than what you’ll see in practice. When choosing a provider, look at billing per successful request, JS rendering support, geo-targeting, and how generous the trial is.

ProxyWing works a level below these, as proxy infrastructure rather than a full API. Many teams pair their own browser setup with our proxies to save on cost and stay in control.

Troubleshooting: why your bypass stopped working

Symptom Likely cause Fix
403 with a captcha-delivery.com link Trust score bottomed out, a hard block Rotate the full identity (IP, fingerprint, cookie), not just the IP
CAPTCHA reappears right after solving Cookie doesn’t match the IP/fingerprint using it Keep the same IP for the whole session and never move a cookie between IPs
Works locally, fails in Docker/VPS No GPU (fake renderer) or missing fonts Use GPU-backed or headful mode and install real fonts
Passes for a while, then blocks everything Behavior pattern caught up with you Slow down, add real navigation, rotate identity periodically
Pages load but API calls return 403 Endpoint needs a cookie from the JS tag Get the cookie via a browser first, then reuse it in the same session
Worked last month, fails now DataDome updated or retrained Re-check your fingerprint setup — expect regular upkeep
Works on one site, blocked on another Each site has its own model Tune per target, since nothing generalizes automatically

DataDome vs Cloudflare, Akamai, and HUMAN (PerimeterX)

Besides DataDome, several other platforms, including Cloudflare, Akamai, and HUMAN are used to protect web resources. PerimeterX became HUMAN Security after the 2022 merger, though a lot of search traffic still uses the old name.

It is also common for some websites to run several systems at once. For instance they can use Cloudflare as CDN with DataDome layered on top is common. The table below shows how these different systems compare:

DataDome Cloudflare Akamai HUMAN (ex-PerimeterX)
Where it runs Any CDN or server and not tied to one platform Only within Cloudflare Only within Akamai’s CDN Edge module or CDN integration
Challenge type Own slider puzzle + invisible Device Check Turnstile Sensor-based, usually invisible Press-and-hold
Tell-tale cookies datadome, tags.js, captcha-delivery.com cf_clearance, __cf_bm _abck, bm_sz, sensor_data _px family
How it learns Trained per customer Mostly network-wide Network-wide, tuned per customer Network-wide
Difficulty to get past High Medium-high Very high High

Is bypassing DataDome legal?

It depends. Scraping publicly available data has been treated relatively permissively by several countries’ laws, including the US. Breaching Terms of Service of your target is a contractual matter, not a criminal one, exposing you to a breach claim or account termination.

Bypassing any form of protection alongside other conduct, including bypassing authentication, accessing non-public data, handling personal data, or generating load heavy enough to degrade a service is a different case entirely.

To be clear, this guide does not encourage credential stuffing, scalping, paywall bypassing, harvesting personal data, or any request volume amounting to a denial of service. This is general information, not legal advice. Jurisdictions differ and case law continues to move. Consult a lawyer about your specific use case before proceeding if it feels necessary.

Final thoughts

Bypassing DataDome is a stack, not a trick, despite what some guides claim. All four layers have to line up together and fixing three still gets you the same 403 as fixing none. Because models are trained per customer, results are local to each site. Test per target and expect the numbers to shift from one to the next.

And don’t stop at the initial setup. DataDome’s tags update and models retrain, so budget for ongoing maintenance from day one.

Article written by:

Daniil Kostin

CEO

Founder of Proxywing. Drives growth across EU, US, and Asian markets, combining B2B strategy with a hands-on focus on product quality, 99% uptime, and responsive support.

All articles by author (64)

FAQ

Yes, it can, but not permanently and not universally. Working setups exist, but DataDome ships tag updates and retrains models continuously, requiring a few changes to the procedure.

Not necessarily. DataDome allowlists verified good bots including Googlebot. These are validated by reverse DNS rather than User-Agent. That’s why spoofing Googlebot’s User-Agent fails that check immediately.

Not really. A residential IP improves one of four scored layers. Use it alongside a browser-matching TLS fingerprint, a hardened browser, and human-like behavior. Without those, your fingerprint still gives you away.

It’s the session token issued after the JavaScript tag reports device signals, bound to the IP and fingerprint that earned it. Presenting it from a different IP triggers an immediate block.

Plain Selenium will get blocked easily. Use SeleniumBase’s UC mode instead, which patches the calls that give Selenium away and stays updated.

Instantly. The decision happens on your first request, in under two milliseconds. A bad fingerprint gets blocked before your scraper even reads the response.

Yes. AI and LLM agents are their own detection category, and it’s one of DataDome’s fastest-growing areas of focus as some sites don’t want these crawlers to access their resources.

No it can’t. Google shut down cached links in 2024, and even when it worked, the data was stale, not live.

No, it’s not. DataDome is a bot management platform. CAPTCHA on the other hand is just one possible response. Most blocks happen silently, with no challenge at all.

It offers several plans: Essentials from $3,830/month, up to Enterprise from $13,270/month. The final cost varies by traffic volume. It’s also available through AWS Marketplace.

Have any questions?