Early September, the explicit-lookup endpoint on my IP-reputation site started seeing tens of thousands of distinct source IPs a day, and most of them queried exactly once. Every request asked about its own address. The sources were residential and mobile ISPs across Europe: BT, Vodafone Italy, Orange, Charter, Telenor.

That shape is somebody validating a residential proxy pool against my endpoint, one exit at a time. And it walks straight past per-IP daily quotas, because a quota caps depth and this has no depth. Thirty thousand exits at one query each sits under any per-IP limit you'd want to set, while spending a full upstream fan-out per request. AbuseIPDB's daily allowance was gone in three hours.

Matching the signature buys you about a day and a half

First attempt: block the signature. wrangler tail showed the fleet's requests were internally impossible under Fetch Metadata. They announced sec-fetch-mode: navigate with dest: document and site: none, which is what an address-bar navigation looks like, while carrying accept: application/json, text/plain, */*, which is axios's default. They carried an Origin, which a GET navigation never has. And a Referer, while claiming site: none, meaning no initiator at all.