The two SerpApi DMCA rulings from July 2026 point in different directions, but neither is a verdict. On July 20, a California court dismissed Google's anti-circumvention claims against SerpApi, because most search results contain no copyrighted work and, for the parts that do, Google hadn't pleaded that copyright owners authorised its SearchGuard defence. On July 31, a New York court let Reddit's near-identical claims against SerpApi and Perplexity go forward, because Reddit had. For scraping teams the practical message is the same from both courts: collecting public pages is one thing, and defeating a named anti-bot system that guards licensed content is another, and the DMCA can reach the second.
Everything below is as of early October 2026. Both cases are at the pleading stage. No court has found that anyone violated the DMCA, and nothing here is a ruling on the merits.
The SerpApi DMCA rulings in one table
Google's case was partly dismissed with leave to amend and has since been refiled. Reddit's mostly survived the motions to dismiss and is in discovery.
| Google v. SerpApi | Reddit v. SerpApi, Perplexity et al. | |
|---|---|---|
| Court / case | N.D. Cal., No. 4:25-cv-10826-YGR | S.D.N.Y., No. 1:25-cv-08736-PAE |
| Filed | December 19, 2025 | October 22, 2025 |
| Judge | Chief Judge Yvonne Gonzalez Rogers | Judge Paul A. Engelmayer |
| Ruling | July 20, 2026: motion to dismiss granted | July 31, 2026: motions to dismiss "predominately" denied |
| Claims | §1201(a)(1)(A) circumvention; §1201(a)(2) trafficking | §1201(a)(1)(A), §1201(a)(2), §1201(b), civil conspiracy, unjust enrichment, unfair competition |
| What survived | Nothing in the original complaint; amended complaint filed August 10, 2026 | (a)(1)(A) and civil conspiracy against SerpApi and Perplexity; (a)(2) against SerpApi |
| What was cut | Results with no copyrighted content: dismissed without leave to amend. Results with copyrighted components: dismissed with leave to amend | §1201(b); unjust enrichment and unfair competition (preempted by the Copyright Act) |
| Status | SerpApi moved to dismiss the amended complaint in late August; pending as of October 3; discovery stayed | Discovery under way; Oxylabs' separate motion to dismiss pending; SerpApi has counterclaimed against Reddit under antitrust law |
What SearchGuard is, and what SerpApi is accused of
SearchGuard is Google's anti-scraping layer on Search, launched in January 2025. According to Google's complaint as summarised in the July 20 order, it sends a JavaScript "challenge" to queries from unrecognised sources. The browser has to run the code and send back information about itself and the user. Real browsers do this invisibly. High-volume automated clients typically can't, and get no results.
Google alleges SerpApi got around it in two ways. It masked automated queries "by misrepresenting the device, software, or location from which the queries are sent." And it solved the challenge once, then syndicated the resulting authorisation to other browsers that never solved it. Reddit's complaint names the same mechanics. Loeb & Loeb's summary of the Reddit opinion quotes allegations about "proxies, fake user-agent strings and 'ludicrous speed' features."
Reddit's case adds a step. Reddit says SerpApi, Oxylabs and AWMProxy scraped Google results pages to harvest Reddit posts, and that Perplexity used the output. Its key evidence, reported by MediaPost when the suit was filed, is a test post that only Google's crawler could index. Reddit says the post's contents showed up in Perplexity's answers within hours. Those are allegations, and the courts accepted them as true only for the purpose of the motions.
DMCA §1201 in plain English
Section 1201 of the Copyright Act makes it unlawful to break or sell tools that break technical locks on copyrighted works. That applies even if you never copy anything. Three provisions matter here (17 U.S.C. §1201):
| Provision | What it prohibits | Type of measure | Who it targets |
|---|---|---|---|
| §1201(a)(1)(A) | The act of circumventing a measure that "effectively controls access" to a protected work | Access control (a gate) | The circumventor |
| §1201(a)(2) | Making, offering or "otherwise traffic[king]" in a technology or service primarily designed to circumvent an access control | Access control | Tool and service providers |
| §1201(b)(1) | Trafficking in tools that circumvent a measure protecting "a right of a copyright owner" (copying, distribution) | Copy/rights control | Tool providers only; there is no matching ban on the act itself |
Two definitions decide most fights. Under §1201(a)(3)(A), to "circumvent" is to "avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner." Under §1201(a)(3)(B), a measure "effectively controls access" if it "requires the application of information, or a process or a treatment, with the authority of the copyright owner, to gain access to the work." That phrase, "with the authority of the copyright owner," is where the two courts split.
The stakes come from §1203. "Any person injured" can sue, and statutory damages run from $200 to $2,500 "per act of circumvention, device, product, component, offer, or performance of service." When the alleged acts number in the billions of queries, that per-act formula is what makes these cases dangerous for defendants.
Why the two courts diverged
The courts mostly agreed on the law. They differed on what each plaintiff had pleaded about authorisation from copyright owners.
Google: no copyrighted work, or no proof of authority
Judge Gonzalez Rogers rejected several of SerpApi's arguments. Google did have standing: §1203's "any person injured" isn't limited to copyright owners. A measure doesn't have to guard only copyrighted material. And Google's masking and token-syndication allegations were enough to plead circumvention. She still dismissed, for two reasons:
- Search results that contain no copyrighted content. Google described results as "compilations of publicly-available information." Where a results page holds nothing protected by copyright, SearchGuard can't be controlling access to "a work protected under this title." That part was dismissed without leave to amend.
- Results with copyrighted components (for example, licensed images in Knowledge Panels). Google didn't allege facts showing SearchGuard "was implemented and functions to control access to copyrighted components … with the authority of the copyright owner[s]." Saying it holds licences wasn't enough without the licence terms. That part was dismissed with leave to amend.
Google refiled on August 10. Per Search Engine Journal, the amended complaint adds licensing terms. One partner deal requires "commercially reasonable efforts" to protect licensed content, and its agreement with Reddit restricts third-party extraction and resale. SerpApi moved to dismiss again, arguing among other things that Google hasn't put the agreements before the court.
Reddit: specific restrictions, pleaded
Reddit could plead what Google originally hadn't. According to Loeb & Loeb's summary of the 63-page opinion, Judge Engelmayer held that §1201 requires only that copyright holders "broadly authorized the implementation of measures," not that they approved a particular technology. Reddit pointed to its user agreement and to its partnership with Google, which includes "specific restrictions on use and requirements to protect against unauthorized access." That was enough. Other points from the opinion, as summarised:
- SearchGuard counts as an access control even though humans pass it freely. The opinion compares it to "a facial-recognition technology programmed to open the door of a home for residents but not for other visitors." Letting people through while stopping bots isn't a loophole. It is how the gate works.
- Perplexity can be a direct circumventor. It allegedly set the scraping parameters and ran the queries through SerpApi, so the (a)(1)(A) claim proceeds against it as well.
- §1201(b) failed because SearchGuard "blocks access to content but does not control what users do with content once it is obtained." It is a gate, not a copy control.
- State-law claims. Unjust enrichment and unfair competition were preempted because they amounted to unauthorised reproduction. Civil conspiracy survived against both SerpApi and Perplexity because the agreement to circumvent is an extra element.
- Standing. Reddit plausibly alleged copyright interests in "tens of thousands of posts and comments," lost licensing revenue, and reputational harm (including from circumventing its content-deletion feature).
Per Law360, SerpApi's lawyer said "the facts are on our side." Perplexity argued the case is about "public information."
SerpApi has since gone on the offensive. In an answer and counterclaims filed on August 28, it accused Reddit of monopolisation and attempted monopolisation under Section 2 of the Sherman Act, alleging that since July 2024 Reddit's crawler rules have admitted Google while shutting out Bing, DuckDuckGo and other search engines, and pointing to its reported $60 million-a-year licensing deal with Google. It also asked for declarations narrowing the DMCA claims, as PPC Land reported. Reddit moved to dismiss the counterclaims on September 25, calling SerpApi a "free rider" (MLex), and on October 2 Judge Engelmayer stayed discovery on the counterclaim until that motion is decided. Discovery on Reddit's own claims, including its Google agreement, continues.
How this differs from hiQ v. LinkedIn and Van Buren
The CFAA cases ask whether you were authorised to use a computer. Section 1201 asks whether you defeated a measure guarding a copyrighted work. Being public helps with the first question and, so far, not with the second.
- Van Buren v. United States (2021) narrowed the Computer Fraud and Abuse Act's "exceeds authorized access" to a gates-up-or-down question: are you entitled to enter that part of the system? Using access you already have for an improper purpose isn't "exceeding authorized access."
- hiQ Labs v. LinkedIn (9th Cir. April 2022) applied that view: scraping pages anyone can see without logging in likely isn't access "without authorization" under the CFAA. But hiQ later lost on breach of contract (its scraping and its fake "turker" profiles violated LinkedIn's user agreement) and settled in December 2022 with a $500,000 payment and a permanent injunction.
SerpApi relied on both cases. Judge Gonzalez Rogers called them inapposite because they interpret the CFAA, not the DMCA. That is the main lesson for anyone whose legal model of scraping is "public data is fair game since hiQ." As both courts read it, the DMCA doesn't turn on whether a page is public. It turns on whether a measure stood between you and a copyrighted work, and whether you got around it.
For a broader legal-and-technical view of one platform, our LinkedIn scraping guide walks through the hiQ history in more detail.
What is decided, and what isn't
Very little is decided. A motion to dismiss only asks whether the complaint, taken as true, states a claim.
- Not decided: whether SerpApi or Perplexity actually circumvented anything, whether the snippets are copyrighted in a way that matters, whether any fair-use-style or other defence applies, and what damages, if any, are owed.
- Decided for now, at the pleading stage only: in the Northern District of California, a gate around uncopyrightable facts isn't a §1201 access control. In the Southern District of New York, a bot-only gate can be one if copyright owners authorised it. District-court rulings bind no other court, and either could be revisited on appeal.
- Still possible: settlement, summary judgment, trial, appeal. At an October 1 conference, as reported by Inner City Press, Judge Engelmayer said Oxylabs' motion was unlikely to be granted and offered magistrate help with settlement.
Practical implications for scraping teams
The risk signal from these cases isn't "scraping" or "proxies." It is a specific pattern: defeating a named technical measure that guards licensed content, often to resell what's behind it. Here is how common practices map against that:
| Practice | Risk signal from these cases | Lower-risk alternative |
|---|---|---|
| Solving or replaying a site's anti-bot challenge tokens (e.g. syndicating one solved session across many clients) | High. Google's token-syndication allegations were held to plead circumvention, and the Reddit court treated a bot-only gate as an access control | Don't build on defeating a named access control; use the provider's official API or a licence |
| Spoofing device, software or location specifically to pass a challenge | High. Cited by both courts as consistent with "avoid, bypass … or impair" | Identify your crawler honestly; where a challenge blocks you, treat it as a "no" |
| Reselling data scraped from a third party's results page (a SERP-as-a-service model) | High. §1201(a)(2) covers offering a service, and the trafficking claim survived against SerpApi | License the data, or collect from the original publishers under their terms |
| Buying scraped data from such a vendor and choosing what it fetches | Medium to high. Perplexity is in the case as an alleged direct circumventor because it allegedly set the parameters | Get vendors to show sourcing and licensing in writing; prefer licensed feeds |
| Collecting public pages with no login or challenge, at polite rates | Low under §1201 (no measure was circumvented); contract, copyright and privacy law still apply | Respect robots.txt and ToS where they bind you; scope fields; avoid personal data you don't need |
| Scraping facts (prices, rankings, URLs) where nothing copyrighted sits behind the gate | Lower for §1201 after the Google ruling, though that holding binds only that case | Still prefer official APIs; don't rely on one district court's view |
| Using official APIs or data licences | Minimal on these theories | The baseline for anything business-critical |
A note on proxies, since they appear in the allegations. Routing requests through residential or geo-located IPs is standard for collecting public data from the right market. Our SERP scraping guide and Google results walkthrough cover that side. What the complaints describe is different: IPs used alongside fake identities and token replay to defeat a specific gate. A ProxyHat gateway with USERNAME-country-US gives you a US vantage point. It isn't a licence, and it doesn't change the legal analysis above. If your use case is Reddit data specifically, check Reddit's own API terms first. Our Reddit scraping guide discusses that path.
What to watch next
- The ruling on SerpApi's second motion to dismiss in the Google case. It will show whether pleaded licence terms are enough for Gonzalez Rogers, which would bring the two courts closer together.
- The Oxylabs motion in the Reddit case, Reddit's motion to dismiss SerpApi's antitrust counterclaim, and whether AWMProxy's part of the case moves at all.
- Any interlocutory appeal on the "authority of the copyright owner" question. An appellate ruling would matter far more than either district order.
This article summarises public court filings and reporting for engineers; it is not legal advice. If your collection depends on getting past a site's technical controls, talk to a lawyer licensed in the relevant jurisdiction before you build on it.






