New Gmail rules, stricter bans

Rakensca

Registered Member
Joined
Feb 16, 2023
Messages
76
Reaction score
18
Hey guys, has anyone else noticed more frequent Gmail bans lately? Not just during auto-registration, but also when using and warming up new accounts. Feels like Google changed their algorithms. What do you think is the main factor now? Behavior patterns? Fingerprints? UDP?

Authorization via BAS, then SMS verification pops up after some time. Replacing proxies with new expensive ones didn’t help
 
Hey guys, has anyone else noticed more frequent Gmail bans lately? Not just during auto-registration, but also when using and warming up new accounts. Feels like Google changed their algorithms. What do you think is the main factor now? Behavior patterns? Fingerprints? UDP?

Authorization via BAS, then SMS verification pops up after some time. Replacing proxies with new expensive ones didn’t help

same here, bans got a lot more frequent lately. feels like it’s more about overall account behavior than just proxy quality. anyone else seeing this?
 
same here, bans got a lot more frequent lately. feels like it’s more about overall account behavior than just proxy quality. anyone else seeing this?
If you enable 2FA right after registration, a ban is guaranteed. I agree with you that it mostly depends on user behavior
Maybe Google has started using AI for detection?
 
If you enable 2FA right after registration, a ban is guaranteed. I agree with you that it mostly depends on user behavior
Maybe Google has started using AI for detection?
mobile carriers make the traffic look closer to real users, which helps with stability.
 
Yes, you need to try
Interesting details about user behavior
 
Hey guys, has anyone else noticed more frequent Gmail bans lately? Not just during auto-registration, but also when using and warming up new accounts. Feels like Google changed their algorithms. What do you think is the main factor now? Behavior patterns? Fingerprints? UDP?

Authorization via BAS, then SMS verification pops up after some time. Replacing proxies with new expensive ones didn’t help
Yeah, I’ve been seeing similar issues lately, even with accounts that were properly warmed up and had human-like behavior patterns. Seems like Google tightened their detection layers again.
 
Yeah, I’ve been seeing similar issues lately, even with accounts that were properly warmed up and had human-like behavior patterns. Seems like Google tightened their detection layers again.
Yes, and it should be noted that it feels tougher now than any other time in the past
 
Hey guys, has anyone else noticed more frequent Gmail bans lately? Not just during auto-registration, but also when using and warming up new accounts. Feels like Google changed their algorithms. What do you think is the main factor now? Behavior patterns? Fingerprints? UDP?

Authorization via BAS, then SMS verification pops up after some time. Replacing proxies with new expensive ones didn’t help
Yep feels that way for a lot of people. Short, forum-ready reply you can drop:


---

Google’s getting stricter; it’s usually not one single thing but a combo: noisy behaviour (mass creation/warm-up patterns), poor IP/device reputation, reused/short-lived phone numbers, and detectable automation/fingerprints from BAS. Replacing proxies alone rarely fixes it because Google looks at the whole signal picture. Best legit fixes are to slow down creation, use stable SIMs or reputable virtual numbers, keep device/browser fingerprints consistent and realistic, add recovery email/backup codes or Workspace for business accounts, and avoid obvious automation patterns. If an account gets flagged, go through Google’s official recovery dodging checks will only make things w
orse.
 
Hey guys, has anyone else noticed more frequent Gmail bans lately? Not just during auto-registration, but also when using and warming up new accounts. Feels like Google changed their algorithms. What do you think is the main factor now? Behavior patterns? Fingerprints? UDP?

Authorization via BAS, then SMS verification pops up after some time. Replacing proxies with new expensive ones didn’t help
https://www.blackhatworld.com/seo/all-the-chrome-anti-detect-browsers-chrome-forks-are-dead-in-the-water-as-of-4-5-days-ago.1748680/

This is what has happened. I have established some workarounds meanwhile.

I will post more about this in the above thread. The solutions are technically relatively hard or rather, need to be precise
 
Like a week ago google dropped num=100 operator, this update was linked to new antiscraping update. Google is overall better at detecting browsers that looks fishy.
 
Don't know for me, google had been good guys, they go to office daily then they come back its no reason for them not to have glory.
Bless you google.
 
Like a week ago google dropped num=100 operator, this update was linked to new antiscraping update. Google is overall better at detecting browsers that looks fishy.
Thank you for this tip. We also found that the main problem in the browser is besides the behavior. We will continue
Don't know for me, google had been good guys, they go to office daily then they come back its no reason for them not to have glory.
Bless you google.
Of course
 
They may have added a QR code that requires uses to scan the screen so that when you login, it verifies you are a human. That was one of the things that gmail added.
 
same here, bans got a lot more frequent lately. feels like it’s more about overall account behavior than just proxy quality. anyone else seeing this?
Everyone is seeing this, the TG support groups of the anti detect providers are full of this, people even laugh at the suggestions from supporters.

This is how it started, I was the first to report.

https://www.blackhatworld.com/seo/all-the-chrome-anti-detect-browsers-chrome-forks-are-dead-in-the-water-as-of-4-5-days-ago.1748680/

Check the very last post, I just did this.

ITs a combination of both proxy and Chrome coming down hard, but proxy quality is definitely definitely at least 50% of the deal breaker, I can confidently say so, I have tested this stuff literally all week and have developed a bot calling 10 paid for abuse APIs
 
They may have added a QR code that requires uses to scan the screen so that when you login, it verifies you are a human. That was one of the things that gmail added.
Bro by the time you get to see that QR code, youre already in the toilet tier trust wise, lol. Even doing the screen thing does not guarantee the account will be created, the issue is much bigger, I was "lucky" enough to discover and report this initially.

The leak vectors are of 3 kinds where Chrome figures out anti detect browsers are running fake forks and an not perfect proxy or slightly bad IP or not perfect multilogin configuration ..any of these factors being off = you are not creating a gmail, not without sms verification, not with sms verification, you might get lucky with a perfect proxy 1 outta 10 times, or 6 outta 10 times if you know how to check a proxy, a proxy just being live doesnt mean a thing.

Ive found ways around it but the technical skill required to pull this off has raised significantly. People better be ready for tutorials or theyll pay with loads of lost time and money until , if they figure things out. In either case, the ones who figure out quickly and adapt will have an easier time, this is a very dynamic field.

I have vast ICT background and I can confidently say that IP quality is the very first issue and the antio detect browsers are all unable to update their apps in a meaningful way, I have provided them with full logs, post mortems etc. You can still do good things with a bullet proof anti detect browser setting(most of providers do not even have the options to set this up, maybe 3 have)AND a perfectly clean proxy.

The proxy providers have flooded the market with bad proxies and never cleaned up their pools , the aanti detect users have believed that default settings are okay and used this bad proxies and made the good proxies bad and eventually Chrome couldnt look away anymore and brought down the hammer.

Its time for the users to learn how to go on, took me a month and I had plenty of free time to test and I have the background, keep in mind an average non technical user might never figure it out or might take much longer. Ive done a proxy checker tool with another member from here, it is working flawlessly and for now, free to test for who wants. The anti detect broswers supporters are either AI and thus useless or basic support agents with no understanding, theyll read from outdated templates. The proxy providers you can expect the same scenario.

Time for the users to deal with this hands on I say.
 
Ive done a proxy checker tool with another member from here, it is working flawlessly and for now, free to test for who wants.
Mind sharing the link here?
Also, what are the signatures that Google uses to identify the browser?
 
Mind sharing the link here?
Also, what are the signatures that Google uses to identify the browser?
Hi there,

There is no link, I am running it on my own server, the testing logic is done, it runs, you can drop me a couple 10 or 100 IPS Ill check them for free for you. The front end stands, the database is done, the back end is done, the API I am doing now, therell be 2 or 4 APIs(I wanna hide where the requests are going and where the responses are coming from) , so that is the current status, but yes, it runs in terminal for now, I wanted to see how the feedback is, the end users sure will be very interested and proxy provider SHOULD be, they can simply segregate the premium IP to sticky sessions and then the not perfect ones to rotating tasks and the bad ones, well, get rid of them, this should keep everyone involved clean and perhaps will expose one or 2 affiliates who deliver bad proxies(seen many dongle based one, amazon fire sticks and such).

Google, how they identify the browser, well, in ML case, the MLX folder name is spilled to network for one, so they do not even need to do much for that. Then, upon first interaction, they can measure how and how fast extensions are loaded, here they also get the usual TCP and l7 info, but more interesting vectors are:

TLS fingerprinting (JA3/JA3S like patterns), the exact TLS ciphers, extensions and handshake order create a fingerprint that can distinguish stock Chrome from custom clients.

Headers and UA information, this is more complicated to manually set up than people think and the anti detect browsers do a pretty bad job at this, they try to make sure pixelscan is passed, but theyre affiliated with them and pixelscan isnt even good at this, pixelscan is "who are you", while TCP is "where you from". So I will leave the easy and obvious parts out here and focus on the more complicated stuff, because Chrome doesnt particularly care about red flags in headers and such, unless its extremly obvious. They just lower the trust score to the profile to a degree where everything is a recaptcha and qr code.

Keep in mind the below info is from Google themselves:

Proxy and reverse‑proxy ports and behavior ,common abuse ports, chain length, visible hop-count.

Cookies and first‑party identifiers , Google cookies, SID, other persistent IDs. Then presence/absence, stale/odd values, or sudden cookies from unrelated geos matter.

Timezone, locale, language and daylight saving offsets.(!!!)

Installed fonts and font rendering, returns differences across platforms and installs. This goes way way beyond just which fonts are installed.

Plugins and mimeTypes (less useful now but but good enough to detect multlogin).

Past abuse reports and threat intel feeds,like Spamhaus listings, phishing&abuse feeds, and reported abuse tied to IPs or ASNs (some of these I get my info for the bot).

And the most difficult ones would be:

Mouse+touch+keyboard event patterns, pointer timing and jitter, scroll patterns, focus+blur behavior aka micro timing

JS execution timing and performance metrics (how long certain DOM/JS operations take) can indicate headless or instrumented(this is basically an anti detect fork) runtimes.
 
Yeah, Gmail’s been nuking accounts hard lately and it’s not just about proxies. I’ve tested it myself even with fresh BAS flows and clean IPs if your behavior looks robotic like instant actions copy-paste or identical timing you’re getting banned. I’ve had way fewer issues since I started using GoLogin and sticking to the same profile and phone number per account instead of recreating everything each time. Also don’t rush log in wait a day just read emails before doing anything. Google’s watching how you act not just where you’re from.
 
Back
Top