iFood decides whether to talk to you by where your network is. On 24 August 2026 a request to ifood.com.br from a datacenter server in Germany came back as HTTP 403 with Cloudflare's "Attention Required!" block page, no storefront behind it. The same evening, four of the five free proxies that managed to connect were served the real iFood site, because they happened to exit inside or near Brazil. The gate is not aimed at proxies; it is aimed at networks that are not Brazilian, which makes the entry ticket obvious: a Brazilian residential address.
Behind that gate is the platform that runs most of Brazilian food delivery. iFood is widely reported at more than 80 percent market share, working with several hundred thousand restaurants and tens of millions of users, processing on the order of a hundred million orders a month, and in 2025 it agreed an interoperability deal with Uber. It is privately held under Prosus and Movile, so those numbers come from market reporting rather than a public filing, and this page treats them as the estimates they are. What is precise is the structure: every storefront is built per delivery address inside Brazil, so reading a city is reading many addresses on a schedule. Below: the jobs, the door in numbers, the type, setup, sizing and limits.
Which proxy fits
Brazilian residential proxies pinned to the city of the addresses you read, driving a real browser, one address per session. A static ISP proxy per account for any restaurant-partner login. A non-Brazilian datacenter exit gets the block page, so datacenter is not an option here for anything but a Brazilian ISP static IP.
iFood as a target
Restaurant storefronts, built per address, with menus and prices set by the restaurants and fees set by iFood. iFood's own grocery and market delivery, priced per store. The market layer is single-country, but it is a big country: prices, promotions and coverage differ sharply between São Paulo, Rio, the Northeast and the interior, so "Brazil" is really dozens of local markets.
iFood renders in the browser behind Cloudflare. Once a Brazilian address is past the gate, storefronts load through iFood's own API calls keyed to the delivery address in the session.
Jobs a proxy is right for
- Menu and price monitoring across Brazilian cities. Chains audit their own listings and their franchisees' markups; independents track competitors; price-intelligence firms build the dataset for a market this size.
- Fee and promotion research by region. Delivery fees, service fees and the promotions in the feed differ across Brazil and change often.
- Coverage by address. Which restaurants reach an address, discovered by entering it, for site selection and competitor mapping.
- Grocery and market pricing. iFood's own grocery prices per store, compared against local supermarkets and quick-commerce rivals like Rappi.
- Localization and listing accuracy. A brand checking that its listings render correctly in Portuguese with the right prices in each city, read from a Brazilian exit, the method in geo-testing with proxies.
Jobs a proxy is not for
Courier accounts. Entregador accounts carry identity and document checks.
Promotion credits and multiple accounts. Accounts attach to a Brazilian phone, payment method and device; farming credits runs against iFood's terms.
Ordering from abroad. A Brazilian payment method and a real address in the delivery area are not network properties.
The door: a selective block
On 24 August 2026 the direct request from our German server got the Cloudflare block page. We put twenty elite HTTP proxies from our free proxy list through the same request: 15 never reached the server, and of the five that did, four received the real iFood homepage (titled "Delivery de Comida e Mercado, iFood") and one was blocked. The four that worked were the ones exiting inside or near Brazil.
Read together, that is a selective block: Cloudflare is refusing networks the operator does not expect a Brazilian customer to arrive from, which includes foreign datacenter ranges, rather than challenging every visitor. There is nothing for a browser to solve, because a block is a verdict, not a test. The fix is a Brazilian residential address, which is what Brazilian customers use. Scraping past Cloudflare explains the difference between a block page and a challenge; how websites detect proxies covers the network side of the decision.
Non-Brazilian network
Cloudflare block page
Brazilian residential exit
real site loads
Address set
one session
Storefronts, prices, fees
record city and time
Type by job
| iFood job | Proxy type | Why |
|---|---|---|
| Menu and price monitoring across cities | Rotating Brazilian residential, city-pinned, session per address | Passes the network gate; reads as a local |
| Fee and promotion research | Rotating Brazilian residential, session per address | Offers are per region and per session |
| Coverage by address | Rotating Brazilian residential, session per address | Each address is one session |
| Grocery and market pricing | Rotating Brazilian residential, city-pinned | Prices are per store |
| Restaurant-partner login | Brazilian ISP (static residential) | One fixed, trusted location per account |
| Anything from a non-Brazilian network | Blocked | The gate refuses it |
For why the two address types are treated so differently, datacenter vs residential proxies.
Free proxies here
The four that worked all exited inside or near Brazil, which is the whole lesson: on iFood, the country of the exit is the only thing that matters at the door, and the Brazilian free pool is small and short-lived. A single manual look is possible if you catch a live Brazilian exit; a schedule is not. Filter our free proxy list to Brazil, verify the exit in the proxy checker, and expect to try several. For a real market read, our Brazilian residential proxies start at $0.44/GB, pay as you go, no KYC.
Setup
- Brazilian residential exit, city-pinned. This is the entry ticket and the localizer at once. A São Paulo address from a São Paulo exit.
- Real browser, cookies kept. Once past the gate the site is an application; keep the session's cookies. Launch flags are in the Playwright proxy guide.
- One session per address. Enter the address, read the storefronts you track, record city and timestamp, rotate. Sticky vs rotating proxy sessions covers the two modes.
- Store prices in reais with the region. Brazil is one currency but many local markets; a price without its city is noise.
- Treat a block on a Brazilian exit as a signal about that exit. Retire it and log it. Avoiding IP bans while scraping has the rest.
Sizing
Auditing a chain across 8 Brazilian cities, weekly:
cities 8
addresses per city 10
pages per address session ~10
sessions per exit per day 4-6
exits in rotation ~30-40 Brazilian residential, city-pinned
Residential meters bandwidth and storefront pages with images blocked are small, so the address list sets the bill. Pricing is pay as you go with no expiring balance.
The boundary
A Brazilian residential address is what turns the block into a page, and it is all the proxy contributes. Courier identity, account links, a Brazilian payment method and iFood's terms, which prohibit scraping, stay where they were. Inside them, a city-pinned Brazilian exit with a real browser lets a legitimate data job read public storefronts the way customers in each Brazilian city see them: one address per session, human pacing, the block rate on a dashboard.
The LatAm super-app that answered with an open door instead of a block is in proxies for Rappi; the general shape of a delivery-marketplace read is in proxies for DoorDash.
Sources
- iFood scale and market position are widely reported (more than 80 percent of Brazilian food delivery; several hundred thousand restaurants; tens of millions of users; on the order of a hundred million orders a month; 2025 Uber interoperability partnership); iFood is privately held under Prosus and Movile, so these are market-reported estimates rather than filed figures.
- HProxy measurement, 24 August 2026: one direct request from a German datacenter server (HTTP 403, Cloudflare block page) and 20 elite HTTP proxies from our free proxy list (15 no connection, 4 real site, 1 blocked).