Doing some large-scale scraping and the usual residential proxy + headless combo gets caught almost immediately now on anything sitting behind the bigger bot-management providers. Not just rate limited, actually served a different page / silently fed garbage data half the time which took me a while to even notice. Is everyone just paying for the expensive anti-detect browser suites at this point (the ones that spoof full TLS/JA3 + hardware fingerprints) or is there still a DIY combo that holds up? And does anyone know if these providers share fingerprint blocklists across their customers, or is getting flagged on one site isolated to that site only?