At its homepage, realtor.com is protected by Kasada, Rate limiting. Typical approach to reach it reliably: Unblocker (signed-payload VM). Difficulty is per-URL, so deep pages — profiles, listings, search — are usually harder.
Signs requests with a closed in-browser JS VM (e.g. TikTok, Kasada, Shape) — generic transport tooling won't do.
Typical access
Signed-payload VM
Why it didn’t pass cleanly
Bot challenge
A JS/bot challenge interstitial was served — a browser must run it.
Detected vendors
Evidence
Detection confidence: high
Homepage-level, datacenter-IP snapshot, June 13, 2026.
This is a homepage-level snapshot and can be inaccurate or out of date — anti-bot vendors update their models continuously, deep pages are usually more protected than the homepage, and difficulty is IP-sensitive: a site can read differently from a clean vs a flagged IP and even flip over time. Treat it as a directional signal, not a guarantee.
The homepage is the open front door. On a real estate site the valuable pages behave differently — here's the plan to characterise realtor.com before you build.
Listing detail
bot-managedCommonly behind PerimeterX/DataDome WAF challenges. This domain signs requests with a closed JS VM, so every page needs a real browser context.
Search / map results
bot-managedWAF + rate-limited — the hardest surface. This domain signs requests with a closed JS VM, so every page needs a real browser context.
Find a real deep URL cheaply from the site’s robots.txt and sitemap.xml, then run each through the anti-bot checker. This is an advisory based on the category and realtor.com’s homepage result — detect the wall, never try to pass a login.