Заголовки запиту
Метадані у форматі «ключ-значення», що надсилаються з кожним HTTP-запитом і описують клієнта, прийманий контент і контекст запиту.
Заголовки запиту - це метадані, які клієнт надсилає з кожним HTTP-запитом у вигляді пар «ключ-значення» перед тілом. Вони повідомляють серверу про клієнта й запит: User-Agent (браузер), Accept і Accept-Language (який контент і мова потрібні), Referer (попередня сторінка), Cookie (стан сесії) та багато іншого. Сервер використовує їх, щоб вирішити, як відповісти.
Для скрапінгу заголовки - велика поверхня виявлення. Реальні браузери надсилають конкретний, узгоджений набір заголовків у певному порядку. HTTP-бібліотеки за замовчуванням надсилають скупий, незвичний набір - часто лише ботовий user-agent і майже нічого більше. Антибот-системи порівнюють ваші заголовки з тим, що надіслав би реальний браузер, і позначають невідповідності.
Зробити заголовки правильними - це більше, ніж виставити браузерний User-Agent. Повний набір має бути узгодженим: Accept, Accept-Language, Accept-Encoding і Sec-* заголовки мають збігатися з браузером, за який ви себе видаєте, у тому порядку, у якому цей браузер їх надсилає. Chrome-заголовок user-agent із заголовками, які Chrome ніколи б не надіслав, - очевидна прикмета.
Анонімність теж живе в заголовках. Прозорий проксі додає X-Forwarded-For, що розкриває ваш реальний IP; elite-проксі не надсилає жодного з них. Коли ви перевіряєте анонімність проксі, чекер інспектує саме ті заголовки, які проксі передає цілі - різниця між elite і transparent записана в заголовках запиту.
The metadata that arrives with every request
Headers accompany each HTTP request and describe the client and what it wants: which content types it accepts, which languages, which encodings, whether it is continuing a session, where it came from.
Real browsers send a specific set in a specific order, and that order is remarkably stable per browser and version. HTTP libraries send fewer headers in a different order, which is a cheap and reliable signal for anyone looking.
Headers also have to agree with everything else. A German exit address sending Accept-Language: ru-RU while the TLS handshake says Python is not a visitor from Germany, and no single one of those signals had to be wrong for the combination to be.
Getting headers right alongside the address
The proxy chooses where you appear to be. Headers have to tell the same story:
A coherent set
Accept-Language: en-US,en;q=0.9 matches login_c_US
Accept-Encoding: gzip saves money on metered products
User-Agent: generated by the browser, not typed by hand
Referer: present when a person would have arrived from somewhere- Send Accept-Encoding: gzip on residential. Compression is the largest single saving available on a metered product.
- Match Accept-Language to the proxy country. Sites use it as much as the address to decide what to serve.
- Do not hand-assemble browser headers. Use a real browser or an impersonation library that also gets the order right.
- Verify what actually arrives: fetch a header echo service through the proxy and read the result.
Header misconceptions
Editing headers does not disguise a library
Order and TLS fingerprint still identify it, and now they disagree with your headers.
More headers is not more human
Real browsers send a specific set. Extra ones stand out.
A proxy does not add or remove headers here
Ours add none. What arrives is what your client sent.
Referer is not always harmless
Sending one that could not exist is a contradiction like any other.
Пов'язані терміни
Дивись на практиці
Готовий використовувати заголовки запиту?
SotaProxy надає доступ до ротуючих резидентських, мобільних, дата-центр та ISP проксі. Без мінімальних платежів.
Почати