Glowing Web Network
Glowing Web Network

Is this site behind Cloudflare?

The most-deployed reverse proxy on the web. Classifies clients via TLS fingerprinting, JS challenges, Turnstile, and managed rules.

Free diagnostic • Confidence scoring • Signal-by-signal breakdown • Recommended client configuration

Try:

Verification keeps this tool free from abuse. For diagnostic and developer use only — run checks on sites you are authorised to access.

What is Cloudflare?

Cloudflare is a global CDN and security platform sitting in front of an estimated 20%+ of the web. Its bot-management layer combines TLS / JA3 / JA4 fingerprinting, browser challenges (Turnstile, "I am Human"), Under Attack Mode, and machine-learning client-classification scores.

Read the full Cloudflare Bot Management glossary entry

How Cloudflare protects sites

  • Browser integrity check + JavaScript challenge ("Checking your browser…")
  • Cloudflare Turnstile — invisible challenge replacing classic CAPTCHA
  • Under Attack Mode (5s interstitial)
  • Managed Rules and rate-limiting by IP / ASN
  • TLS fingerprint (JA3/JA4) matching against known HTTP-client libraries
  • WAF rules that inspect headers and request shape

Detection signals we look for

  • server: cloudflare response header
  • cf-ray response header (Ray ID)
  • cf-cache-status header
  • __cf_bm and cf_clearance cookies
  • Challenge page containing /cdn-cgi/challenge-platform/

Recommended Scrappey client configuration

For authorised access only — your own properties, contractually permitted scraping, QA, monitoring, accessibility audits, and similar use cases. Always respect the site's terms of service and applicable law.

  • Use a real browser engine — raw HTTP clients produce JA3 hashes Cloudflare recognises and classifies as non-browsers.
  • Persist cf_clearance cookies across requests in a Scrappey session with sessionTtl.
  • Prefer residential proxies for traffic that needs to match a regular user — datacenter IPs receive stricter scrutiny.
  • Match the proxy country to the site's primary audience to keep request geo consistent.
  • When Turnstile is configured by the site owner, request it through Scrappey with antibot: "cloudflare" and respect the site's terms of service.

Create a free account to run the configuration above — 150 credits included, no card required.

Cloudflare FAQ

How do I know if a site uses Cloudflare?

Paste the URL above — we check for the cf-ray and server: cloudflare headers plus characteristic challenge HTML. The check takes about one second.

Why does my Python requests or curl script get blocked on Cloudflare sites?

Cloudflare's managed challenge fingerprints the TLS handshake. requests and curl produce JA3 hashes that are instantly classified as non-browser HTTP clients, so the WAF replies with a 403 or a challenge page. For authorised access, run a real browser or a TLS-mimicking library like curl_cffi.

What is cf_clearance?

A cookie issued after a successful challenge clearance. It is bound to your IP and User-Agent — moving the cookie to another machine invalidates it. Scrappey sessions hold it for you.

Related concepts

Deeper reading on the techniques and signals that surround Cloudflare.

Concept map

How anti-bot protection fits together

Hover a vendor or technique to see the connections. Click any node to read the full glossary entry. The lines show which detection techniques each vendor leans on.

6 vendors · 8 techniques · 27 connections
Hover · click a node
CloudflareDataDomePerimeterXAkamaiKasadaImpervaTLS Fingerprint (JA3/JA4)Browser FingerprintJS ChallengeCAPTCHACookie BindingIP ReputationBehavioural SignalsProof-of-Work
Vendor Technique
footer-frame

Start building with Scrappey

Try It For Free. No Subscription Required. No Credit Card Required. Instant Set-Up. 150 Free Requests Are Waiting For You!