CAPTCHAs
CAPTCHA pages mean the target site detected something off about your request — not necessarily a "bot," just that something doesn't add up. helodata supplies the IP; the rest is your client's job.
Common detection signals (in order of importance)
IP reputation — has this IP been hammering the target recently?
Header consistency — UA, Accept-Language, Sec-CH-UA-* must agree with each other and with the IP's country
TLS fingerprint — JA3 / JA4 hash matching a known bot library
Behavior — request pattern, timing, mouse / scroll on JS pages
Quick wins
In rough order of effort vs payoff:
1. Use a session, not rotation, for multi-step flows
Bot detection counts how many requests came from each IP. A sticky session looks like one user across the flow; pure rotation looks like a million one-page users — that's a classic bot signal.
helo_s1a2b3c4d5e-type-res-region-us-session-job1-sesstime-302. Align headers with the IP geo
If your exit IP is in Germany, your headers should look German:
Accept-Language: de-DE,de;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (... a modern browser UA from a major OS ...)Mismatched Accept-Language (e.g. zh-CN from a US IP) is a strong signal.
3. Send a complete browser header set
A bare requests.get() sends fewer headers than any real browser. Pad it:
4. Use a JS engine for JS-heavy sites
Targets that ship behavioral fingerprinting (navigator.webdriver, mouse movements, canvas) need a real browser — use Playwright or Puppeteer with stealth plugins.
5. Switch to mobile
If the target trusts mobile devices more (a common pattern), switch from type-res to type-mob. Pair with a carrier ASN:
What about CAPTCHA solvers?
helodata doesn't solve CAPTCHAs. Common patterns to combine:
2Captcha / Anti-Captcha / CapSolver — pay-per-solve services that return the token
puppeteer-extra-plugin-recaptcha— Puppeteer plugin that wires the token inBrowser-fingerprint-aware antidetect browsers — AdsPower, Multilogin — these handle the fingerprint side, leaving you to fetch the token
For Cloudflare's invisible challenges (1020, JS challenge), a real Chromium with stealth almost always beats a CAPTCHA solver.
When the target just hates the IP
If you've matched headers, fingerprint, and behavior and still see a CAPTCHA — that exit IP is burnt for this target. Rotate:
Gateway: drop the session, get a fresh IP
ISP: switch to another IP from your batch; consider requesting a replacement if it persists across multiple IPs from the same batch (replace IP)
Coming soon
helodata's Web Unblocker handles all of the above transparently — JS rendering, header rotation, CAPTCHA, retries. Join the waitlist if this is the pattern you keep solving.
Last updated
Was this helpful?