Proxies for Sephora solve a problem that appears before the first product page loads: the site decides which country you are in, from your IP address, and serves you that country's store. On 24 August 2026 we sent a plain request to sephora.com from a German broadband connection with an English Accept-Language header. The answer was an HTTP 301 to sephora.de. A datacenter server in Europe got the same redirect. Only after the redirect did Akamai's Access Denied page appear, refusing the plain client. For anyone who needs to see what Sephora sells, and for how much, in a country they are not sitting in, the exit address is the first requirement and everything else follows.
Sephora, owned by LVMH, operates more than 2,700 stores in 35 countries, with more than 500 across the Americas (Sephora, about us), and its online business is a set of country storefronts rather than one global site. Each has its own currency, assortment, promotions and launch calendar, and access to the biggest sales is staggered by loyalty tier.
What proxies work best for Sephora?
Residential proxies exiting in the country of the storefront you are reading, behind a real browser that runs Akamai's sensor. A static ISP proxy in the account's own country for any logged-in Beauty Insider session. Nothing from a datacenter range, which was refused on contact.
Sephora is a set of country stores, and the IP chooses yours
The redirect is the visible part. The cookies our refused request still received show the rest: current_country, site_locale and site_language were set from the address, and the akacd_HEADLESS_SFCC_PROD cookie marks the storefront as a headless build on Salesforce Commerce Cloud, the platform behind the country sites. Three consequences follow.
- There is no global Sephora price. sephora.com, sephora.ca, sephora.fr, sephora.de, sephora.co.uk and the rest price in their own currencies with their own promotions. A product tracker needs one row per country per product, and each row has to come from an exit in that country.
- Assortment differs. Brands and shades launch by market; a product can be sold out in one country, unreleased in another, and never listed in a third. Availability monitoring is per storefront.
- The choice cannot be overridden by headers. Our English
Accept-Languagechanged nothing. The country is a function of the IP, which makes geo-targeted residential exits the only reliable way to read a specific store. Geo-testing with proxies covers verifying the exit before trusting the data.
Request from an IP
country read first
301 to the country site
we got sephora.de
Akamai judges the client
browser or refused
That country's catalog
currency, stock, promotions
In the United States there is a further wrinkle: Sephora at Kohl's shop-in-shops sell Sephora's assortment through kohls.com, which is a separate site with its own Akamai layer (it refused our plain client too). A complete US read of a product can mean two storefronts.
The Beauty Insider tiers stagger the sale
Sephora's loyalty program has three tiers. Insider is free to join; VIB is reached with $350 of fulfilled merchandise purchases in a calendar year; Rouge with $1,000 (Sephora, Beauty Insider terms and conditions). During the twice-yearly savings events the discount follows the tier, 20 percent for Rouge, 15 for VIB and 10 for Insider, and access opens in a staggered fashion with Rouge first (Yahoo Shopping, Sephora savings event by tier, 2026). Members also get early access to new launches and limited editions, which is where the items that sell out go first.
For a monitoring project this creates two very different jobs. Watching public prices, restocks and launches is anonymous reading at scale. Watching what an account sees during early access is a logged-in session with a tier attached, and a tier is an identity. Both need proxies; they need different kinds.
What Akamai did to a plain client
After the redirect, both of our test requests got the same response from AkamaiGHost: a 403, a page titled Access Denied, and no product. The decision rested on the request, the TLS handshake (Akamai reads the JA3/JA4 signature before any HTTP is exchanged) and the header set a real browser sends and a script does not (what is JA3/JA4 fingerprinting). Past the door, Akamai Bot Manager scores the session continuously through its sensor script and the _abck cookie, with per-IP rate limits on top (how the _abck cookie works, how to scrape past Akamai). The proxy's part is narrow: a residential address in the right country, held for the session, kept under the rate that draws a challenge.
Which proxy type fits which Sephora job
| Sephora job | Proxy type | Why |
|---|---|---|
| Cross-country price and assortment comparison | Rotating residential, one pool per country | The IP chooses the store; each store is its own list |
| Launch and restock monitoring | Rotating residential in that country, sticky per session | Frequent reads of a few pages, shopper-paced |
| Review and rating collection | Rotating residential | Separate endpoints, own limits |
| Beauty Insider account, early access, cart | Static ISP in the account's country | Tier is an identity; the session must keep one address |
| Sephora at Kohl's reads | US rotating residential | A second site with its own Akamai layer |
| Pipeline and liveness tests | Datacenter or free | Refused on contact; only proves traffic flows |
Rotating residential addresses are real home connections in the country you choose, so the redirect lands where you want and the reputation check passes. ISP proxies never change, which a logged-in tiered account needs. Mobile proxies are the heavyweight tier for sessions that keep getting flagged and are rarely needed for catalog reading. The residential flavors are compared in rotating vs static residential proxies.
Setup
Pin the country before anything else. Choose the storefront, exit from a residential address in that country, and confirm the redirect landed on the domain you expected. A US pool for sephora.com, a French pool for sephora.fr, and so on. Do not read the French store through a US exit and a language switch; the site will not let you, and the price would be wrong if it did.
Drive a real browser and keep its cookies. Playwright or Puppeteer behind the proxy, profile persisted, so the sensor sets _abck and the country cookies survive (proxies for Playwright, proxies for Puppeteer).
Choose rotation by state. Anonymous product reads take a fresh exit per session, with a sticky window inside the session so the cookies stay valid. A logged-in account holds one static address for its entire life, in its own country, and never shares it with another account. The mechanics are in sticky vs rotating proxy sessions.
Pace launches like a fan, not a bot. Restock watchers tend to poll one product page every few seconds from one address, which is the most recognizable pattern a launch page sees. Spread the polling across exits and jitter the interval.
Sizing
For reading, the per-exit rate is the constraint and the country is the multiplier. Find how fast one residential IP behind a browser can read a storefront before challenges appear, keep every exit under it, and run a separate pool for each country you monitor. Because a browser is mandatory, budget for full page loads rather than bare HTML, a difference we measured in headless browser proxy bandwidth cost.
For accounts, one static ISP address per account, in the account's country, never shared. Two accounts behind one address is the pattern a loyalty program links, and a linked pair loses its tier faster than any proxy can help. Our pricing is pay-as-you-go with a balance that does not expire, so a sale week and a quiet month cost only what they use.
Free versus paid for Sephora
A free proxy is a shared datacenter address without a browser, and that client was redirected and then refused by sephora.com on its first request in our test. A free proxy in a given country will at least show you which storefront the redirect lands on, which is a legitimate one-off check, and our free proxy list with the proxy checker covers it. Reading a Sephora price or watching a launch takes paid residential in that country, from $0.44/GB pay-as-you-go with no KYC, behind a real browser. The wider line is in datacenter vs residential proxies.
Staying unblocked
- Match exit, storefront and language. A US exit on sephora.fr is a mismatch the site resolves against you; read each store from inside it.
- Never move a logged-in account between addresses. A tiered account that changes country or IP mid-session is the cleanest fraud signal Sephora has.
- Keep the sensor cookies. Discarding
_abckevery request restarts the sensor and reads as a bot regardless of the address. - Poll launches from many exits, slowly. One address hammering one product page is what launch defenses are built for.
- Log the challenge rate per country. Pools are scored separately; a rising 403 share in one country is the signal to slow that pool down. The general hygiene list is in avoiding IP bans while scraping.
What a proxy does not do here
A proxy lands you in the right country and keeps sessions apart. It does not run Akamai's sensor, does not raise a Beauty Insider tier, does not open early access before the tier's window, and does not make many accounts look like many people to a loyalty program that reads payment, address and device. Scraping Sephora's sites and operating multiple accounts both run against Sephora's terms, and that risk stays with you whatever the addresses are.
What a country-correct residential exit does is let you read the store a local customer sees, at a local customer's pace, without the redirect deciding for you. Start with the free proxy list to see where each country's redirect lands, then read each storefront through residential from $0.44/GB, one pool per country, and keep every account on an address of its own.
Sources
- Sephora, About us: more than 2,700 stores in 35 countries.
- Sephora, Beauty Insider terms and conditions: the Insider, VIB and Rouge tiers and their spend thresholds.
- Yahoo Shopping, Insider, VIB, or Rouge? What to get during Sephora's savings event 2026, per your tier: the 20, 15 and 10 percent discounts and staggered access.
- Akamai, Bot Manager: the vendor behind the Access Denied page.
- Cloudflare, JA3/JA4 TLS fingerprinting: fingerprinting before the first HTTP request.
- HProxy test on 24 August 2026: plain GET requests to sephora.com from a German residential connection and from a European datacenter server, both redirected with a 301 to sephora.de and then refused with an Akamai Access Denied page; kohls.com refused the same client with an Akamai Access Denied page.