Dual Login
Guides

eBay Stealth Account Setup Guide (2026): A Field Manual

Dual Login Team·2026-08-12·22 min read

eBay Stealth Account Setup Guide (2026): A Field Manual

How eBay actually links accounts — and the profile, fingerprint, proxy and payout setup that keeps a new selling identity genuinely separate.

Isolated browser profiles arranged for an eBay stealth account setup guide, each with its own fingerprint, data directory and proxy

Most writing on this subject reads like a shopping list. Buy a proxy. Buy a phone number. Buy a browser. Done. Then the account eats an MC011 on day four, and nobody can tell you why, so the next attempt is the same list with a more expensive proxy.

That approach fails because eBay is not running one check you can defeat with one purchase. It is running a correlation engine. Every signup, listing, login, message and payout gets compared against the graph of everything eBay already holds — and the question it asks is not "is this person suspicious?" but "does this new account resemble something already on file, particularly something we already removed?" One strong match is enough. It does not matter that the other twenty signals were perfect.

So this guide is organised the way the problem actually is: identify every layer that can produce a match, close each one deliberately, then run the account in a way that does not re-open them next Tuesday. I have written it as a working document rather than an overview. Some of it is tedious. The tedious parts are where accounts die.

What "stealth" actually means — and the line you need to see clearly

The word is forum inheritance and it misleads people. Nobody is invisible on eBay. You are logging into a platform that knows your listing history, your buyer messages and your bank account. Stealth has never meant unseen. It means unmatched: a new selling identity that does not resolve, in eBay's graph, to an identity it already knows.

That distinction matters because it tells you what to spend effort on. You are not trying to look like nobody. You are trying to look like a different, entirely ordinary seller — one whose device, network, paperwork and behaviour are internally consistent and share nothing with your other accounts.

The part most guides skip

eBay permits multiple accounts. This is written policy, not a loophole. Sellers routinely run one account for camera gear and another for vintage workwear, because feedback, category standing and buyer expectations do not mix well. Agencies run an account per client. None of that is prohibited, and you can read the current rules yourself in eBay's own help centre — look for the multiple account policy and the user agreement, and re-read them rather than trusting a Reddit summary from 2021.

What eBay prohibits is using a second account to escape a restriction on the first. That is a breach of the user agreement, and eBay enforces it aggressively and retroactively — including closing accounts that traded cleanly for months once the link surfaces. Separately, and much more seriously: registering with someone else's name, identity documents, tax ID or bank details is fraud in most jurisdictions, and no amount of browser configuration changes that.

So the version of this that is defensible, and the only version worth building, looks like this. A genuinely separate identity: a different legal entity that you actually own (a second registered company, or a partner's business with their knowledge and consent), its own bank account, its own address that you genuinely control, its own phone, its own email. Then — and only then — the technical work of keeping that identity unlinked, which is what the rest of this guide covers.

If you are rebuilding after your own suspension, be honest with yourself about the risk you are accepting. It is not zero and it never becomes zero. Sellers who treat a rebuilt account as permanent infrastructure lose more than sellers who treat it as revenue that might stop.

Think of these as six independent chances to be matched. You need all six closed, and they fail in different ways.

1. Identity and financial

The strongest layer by a wide margin, and the one no browser can help with. Legal name, tax ID, bank routing and account number, payout recipient, billing address, phone. eBay verifies these for managed payouts, and a bank account is effectively a primary key. Two accounts sharing one payout destination are the same seller and eBay does not need to guess.

2. Network

IP address, subnet, ASN, and the reputation of both. Consumer ISPs hand out addresses that rotate slowly, so a residential IP is a reasonable fingerprint on its own over a week. Datacentre ranges are worse than useless — they are pre-flagged, and a "private household seller" arriving from an AWS range in Frankfurt is a story that falls apart immediately.

3. Device and browser

Cookies, localStorage, IndexedDB, cache entries, service workers, evercookie-style storage, and then the fingerprint proper: canvas and WebGL rendering, audio stack, installed fonts, screen metrics, timezone, language list, hardware concurrency, plugin and codec support. This is the layer where most people believe they are covered and are not. It is also the layer you have the most control over, which is why it is worth doing properly. If you want the full picture of how the correlation works, I wrote it up separately in how websites detect multiple accounts on the same device.

4. Behaviour

Login times, session cadence, typing rhythm, how fast you move from dashboard to listing form, whether you always sort your orders by the same column. Individually noise; collectively a habit signature. This layer rarely triggers a ban on its own but it raises confidence in a match made elsewhere.

5. Catalogue

Your listings are public and machine-comparable. Identical titles, identical description HTML, identical photographs, the same handling time and the same return policy wording across two "unrelated" sellers is a match anyone can make — including your competitors, who report each other more often than sellers expect.

6. Third-party and cross-platform

Shipping labels, tracking numbers tied to one collection address, the phone number on a courier account, a support email you also used on your old account, a Facebook pixel on the domain in your listing footer. Data leaves your control the moment it touches a partner.

Pre-flight: assemble the identity before you open a browser

Do not register first and improvise the rest. Every asset you improvise later is an asset you will end up borrowing from an existing account, and that borrowing is the actual failure mode.

Asset Why eBay cares Where people slip
Legal identity or entity Drives verification, tax reporting, payout ownership Reusing the same sole-trader identity across two "separate" shops
Bank account and payout recipient Effectively a unique key; verified against name One bank, two accounts — an instant, undeniable link
Tax ID (EIN / UTR / VAT) Required for payouts above thresholds Sharing a tax ID between entities that claim to be unrelated
Phone number SMS verification and recovery; stored long-term A VoIP number from a block eBay has already burned
Physical address Registration, return address, courier pickup Same return address printed on labels from two accounts
Email Recovery graph and support correspondence Same provider, same alias pattern, same recovery mailbox
Browser profile Cookies, storage, fingerprint One browser, several accounts, "but I cleared cookies"
Exit IP Network reputation and geography Datacentre proxy, or an IP shared with a suspended seller

Write these down per account, in one place, before day zero. A boring spreadsheet with a row per identity — entity, bank, phone, address, email, proxy endpoint, profile name, registration date — prevents about eighty percent of the mistakes in this article. Not glamorous. Extremely effective.

Building the browser layer

This is the part that is actually technical, so I will be specific.

One profile, one data directory

A browser profile is not a window or a tab; it is a directory on disk. Chromium keeps cookies, localStorage, IndexedDB, cache, service workers and site permissions inside the path passed to --user-data-dir, and the Chromium documentation on the user data directory spells out what lives where. Two accounts sharing that directory are one account with two logins, no matter how carefully you sign out.

So the first rule is mechanical: one eBay identity, one dedicated data directory, forever. In Dual Login each profile gets its own directory under data/profiles/<id> and its own operating-system process, which means separate memory, separate storage and no shared cookie jar. That also means a crash in one profile cannot take the others down, which matters when you have eleven open.

What this does not mean is "clear cookies between accounts". Clearing cookies deletes the easy identifier and leaves every hard one intact. Cache-based tracking, storage partitions you forgot about and the fingerprint itself all survive it. Clearing cookies is what people do instead of isolation, and it is why they get linked.

The fingerprint has to tell a boring story

Here is the mental model that fixes most fingerprinting mistakes: you are not minimising uniqueness, you are maximising plausibility. A profile that reports no canvas, no WebGL, no fonts and no plugins is not anonymous — it is a rare and memorable configuration that no real customer has. EFF's Cover Your Tracks makes this visible in about thirty seconds: the goal state is "randomised, coherent, unremarkable", not "blank".

The canvas surface is the classic example. A script draws text and shapes to an offscreen canvas, reads the pixels back with toDataURL(), and hashes the result; tiny differences in GPU, driver and font rasterisation make that hash remarkably stable per machine. WebGL goes further, exposing vendor and renderer strings plus dozens of numeric limits. If you want the detail on that specific surface, see WebGL fingerprint spoofing explained, and for the broader how-to, how to change your browser fingerprint.

One implementation point that matters more than any individual value: where the spoof happens. If a tool overrides these properties with injected JavaScript, the override is itself detectable. A patched function has a different toString() output, sits in the wrong place in the prototype chain, and is frequently absent inside Web Workers and cross-origin iframes — so a detector reads one value on the main thread, a different value in a worker, and concludes the browser is lying. Dual Login applies fingerprints natively inside the engine, below the JavaScript layer, so there is nothing to inspect and no worker/main-thread disagreement to catch. That difference is the whole reason a purpose-built engine beats a bundle of extensions.

Coherence: the checks to run on every new profile

A fingerprint is a story about a machine. Every field has to belong to the same machine.

Signal Must agree with Typical giveaway
User-Agent and navigator.platform The OS you are claiming Windows UA serving a macOS font list
Timezone The proxy exit city UTC+0 on a seller who ships from Chicago
navigator.languages Country and buyer audience en-US only, on a German storefront
Screen size and devicePixelRatio Plausible real hardware 1366×768 at 3× pixel ratio
WebGL vendor and renderer The OS, and the hardware era Google SwiftShader on a claimed gaming desktop
Font list OS plus normally-installed suites Windows with no Segoe UI
hardwareConcurrency and memory The device class 32 cores on a budget laptop story
WebRTC candidate IPs The proxy exit, not your LAN Real 192.168.x.x leaking beside a Dutch IP

The last row deserves emphasis because it is silent. WebRTC can enumerate local and public addresses independently of your proxy, so a profile can be perfect everywhere else and still publish your real IP to any page that asks. Dual Login masks WebRTC to the proxy exit natively; if you are using something else, test it, do not assume it.

Proxies: geography, not just anonymity

A proxy is not there to hide you. It is there to place you somewhere specific and keep you there. That means:

  • Residential or mobile, never datacentre. Datacentre ranges are classified before you connect.
  • Sticky sessions. A session that hops IP mid-listing looks like a hijacked account. Aim for a session that holds for hours, ideally days, and drifts within one ISP and one metro area.
  • Match the paperwork. The exit city should be the city on the account. If the business address is in Leeds, exiting in Bucharest is not a fingerprinting problem, it is a story problem — and eBay's risk team reads stories.
  • One proxy, one profile. Sharing an exit between two accounts re-links what you separated in the browser. This is the single most common way a properly configured setup fails.
  • Check what came before you. Residential pools are shared over time. If a suspended seller used your exit last month, you inherit that. Rotate away from an endpoint that produces friction on day one rather than trying to push through it.

Mobile IPs deserve a mention: they are carrier-NAT'd, so hundreds of real people share them, which makes them noisy in your favour and expensive. They are worth it for high-value accounts and overkill for a ten-listing test. The pairing mechanics — sticky windows, ASN matching, per-profile assignment — are covered end to end in the antidetect browser with residential proxies playbook.

What not to randomise

This trips up careful people. Once an account exists, its device must stop changing. Real hardware does not swap GPU vendors on Thursday. Generate the fingerprint once, pin it to the profile, and leave it alone; the only legitimate drift is a browser version bump, which real users also get. Re-rolling a fingerprint on an established account is a fresh-device signal on a known account, which is exactly the shape of a stolen login.

The first thirty days

A correctly built account can still be killed by an impatient first week. Selling limits exist precisely to make new sellers prove themselves slowly, and trying to sprint past them is the loudest thing you can do.

Day zero: warm the profile before you register

Open the profile and use it as a person would. Browse eBay as a guest. Search things the identity would plausibly search. Read a couple of listings, look at a competitor, visit two or three unrelated sites so the profile has a cookie jar that is not exclusively eBay. Thirty to sixty minutes over a day or two is enough. A brand-new browser whose entire history is signin.ebay.com is a fingerprint of its own.

Registration day

Register as a buyer first if the identity plausibly would. Complete the profile properly: real photo-free but filled-in details, verified email, verified phone. Add a payment method. Then stop for a day.

Type your details in rather than pasting them from a password manager into every field at machine speed. Paste-only form completion with zero keystroke variance in a signup flow is measurable, and it is measured.

The first seventy-two hours

Buy something small. Genuinely — a five-dollar item you want, from a seller with good feedback. Pay for it, receive it, leave feedback. A buying history before a selling history is the cheapest credibility available and almost nobody does it, which is a shame, because it is the difference between "account created three days ago" and "account with a transaction record".

Avoid logging in from a second device in this window. If you must, it needs to be a device that fits the story, on the same proxy.

Weeks one and two: the first ten sales

List inside your limits, not at them. New sellers commonly start with a small monthly allowance — something in the region of ten items or a few hundred dollars, though eBay adjusts this per account and per market, so read what your own dashboard says rather than trusting a number from a forum. List three or four items. Price them to actually sell. Ship the same day, upload real tracking, answer messages within hours.

What you are building is not revenue, it is a resolution record: items delivered, no cases opened, no late shipments. That record is what a limit-increase request is graded on, and it is what makes a future dispute get resolved in your favour instead of against you.

Weeks three and four: asking for room

Once you have ten or so completed transactions with clean tracking and positive feedback, request an increase. Ask for a modest one. Then run at the new ceiling for a couple of weeks before asking again. Accounts that ratchet up gradually end up with far higher limits, far faster, than accounts that demand a hundred-item allowance in week two and get flagged for the ask.

The same patience logic applies across marketplaces, incidentally. The account-preservation habits transfer almost directly to Amazon, which is stricter still — see the Amazon seller ban-avoidance playbook if you sell on both.

Payments and payouts: the layer with no technical fix

This is where I see the most expensive failures, because it is the one layer where a browser cannot save you.

eBay handles payouts directly. To receive money you supply a bank account, an identity that matches it, and a tax ID above the reporting threshold. Those values are verified against external sources and stored permanently. If two accounts point at one bank account, they are linked, full stop — and the link surfaces at the worst possible moment, which is when the first payout is processed and you already have unfulfilled orders.

So: separate entity, separate bank account, separate tax ID, separate verified name. If that is not achievable for the identity you are building, stop building it. Everything else in this guide is wasted effort behind a shared bank account.

Expect holds. New sellers routinely see funds held until delivery confirms, sometimes for around three weeks on the first transactions. Plan cash flow for that; a seller who cannot fund shipping because the payout is held ships late, and late shipping is a defect rate, and a defect rate is a restriction. The payment layer and the operational layer are the same layer in practice.

The mistakes that actually kill accounts

Every one of these has ended an account I have watched.

Reused photographs

Images carry EXIF — camera model, serial, sometimes GPS. Strip it. But also understand that stripping metadata does not defeat perceptual hashing: the same photo of the same jacket, re-cropped, is still recognisably the same photo. Re-shoot inventory per account. Different background, different angle, different light. Yes, it is work.

Copy-pasted listing text

Description HTML is a fingerprint. Same template, same bullet ordering, same slightly-odd phrasing in the returns paragraph, same typo. Write per account, or at minimum maintain genuinely distinct templates with different structures.

The return address on the label

You can isolate every browser in the world and then print two accounts' labels with the same collection address and the same courier account number. Couriers share data with marketplaces. If two identities dispatch from one physical place, treat them as linked and plan accordingly.

The password manager

One vault, autofilled across profiles, is a linking mechanism with a friendly UI. It fills the same recovery email, the same phone, occasionally the same address, and it does it at machine speed. Use per-profile credentials and per-profile vaults or entries, and turn autofill off on registration flows.

The support ticket

Contacting support about account A from account B's session, or from an email tied to a closed account, hands eBay the link directly. Every support contact goes through the profile that owns the account. No exceptions, including "just this once, from my phone".

The phone

One number across accounts links them permanently, because numbers are stored in the recovery graph forever. Also: cheap VoIP blocks are frequently pre-burned. A real SIM in a real device is unglamorous and works.

Cross-tab bleed and third-party logins

Signing into your personal Google account inside a selling profile to check an email links that profile to your entire identity graph. Signing into a shared analytics or courier dashboard across profiles does the same, one layer up. Keep profiles single-purpose.

Comparing the three ways people do this

Approach Isolation quality Cost per account Practical ceiling Where it breaks
Separate physical machines Excellent Very high 2–3 accounts Cost, desk space, and the day you copy a file between them
Virtual machines Good storage isolation, weak fingerprint isolation Moderate (RAM-bound) 3–5 per host VM GPU strings and screen metrics are recognisable; every profile looks like a hypervisor
VPN plus separate Chrome profiles Poor Near zero 1 Shared fingerprint, shared exit IP, shared everything but cookies
Antidetect browser, per-profile fingerprint and proxy Strong on both layers Low Dozens to hundreds Operator error — reused proxies, reused addresses, reused photos

The honest summary: virtual machines were the right answer in 2016 and are an expensive half-answer now, because a VM does not fix the fingerprint, it just gives you a distinctive one. A VPN with multiple Chrome profiles fixes nothing at all — same device fingerprint, same exit IP, and the whole point of profiles is convenience, not isolation. A purpose-built engine is cheaper than either and isolates both layers, which is why it became standard for anyone running more than two identities. If you want the specific eBay-shaped comparison, I went deeper in the best browser for managing multiple eBay accounts.

When a new account gets restricted anyway

It happens. Work the layers in order of strength rather than guessing.

Read the actual notice. eBay's codes are vague but not meaningless. A restriction referencing a link to another account is a different problem from a verification hold or a selling-limit block, and the fixes do not overlap.

Check the financial layer first. Did the bank account, tax ID, name or address touch another account, ever, including years ago? This explains the majority of instant restrictions and no browser change will help.

Then the network. Was the proxy exit shared with another profile, even briefly during setup? Did the endpoint rotate into a range that belongs to a different country? Look at your logs, not your memory.

Then the device. Did the profile ever open the other account, even to "check something"? Did you restore a backup into the wrong profile? Was the fingerprint regenerated mid-life?

Then the catalogue. Are any photos, titles or description blocks shared with a live or closed account?

If the link is financial or identity-level, appealing is usually futile and the account should be written off. If it is verification or limits, respond with documents promptly and completely; those clear regularly. Do not open a third account to appeal the second. That escalates a single restriction into a pattern, and patterns get whole clusters removed.

Running this as a team

At some point somebody else needs access, and that is where hard-won isolation usually collapses.

Hand over the profile, not the credentials. If a virtual assistant logs into an account from their own laptop and their own home IP, you have introduced a second device and a second network to an established account, and you have done it without any of the coherence work. The correct pattern is that the VA operates the same profile — same fingerprint, same proxy — through the manager, with access scoped to just the profiles they need.

Three operational rules that save trouble:

  1. One operator per account at a time. Two people driving one profile from two cities produces simultaneous sessions from two IPs, which is the exact shape of a compromised login.
  2. Scope permissions per person. A packer needs order visibility, not the ability to change the proxy or export cookies.
  3. Keep an audit trail. When an account gets restricted, the first question is what changed and who changed it. Guessing costs days.

Dual Login handles all three natively — per-member capabilities, profile-visibility scoping, a full audit log of every state-changing action, and an open-lock so one profile cannot be launched on two machines simultaneously. If you are building the same thing out of shared passwords and a group chat, expect to learn these rules the expensive way.

FAQ

Holding multiple eBay accounts is permitted by eBay's own policy, and building a second selling identity on a genuinely separate legal entity, bank account and address that you actually own is not illegal. Two things change that: using a second account to evade a restriction on another (a user-agreement breach eBay enforces retroactively), and registering with another person's identity documents or bank details, which is fraud. Read the current policy on eBay's help site before you start, not a forum summary.

Can I just use Chrome profiles or incognito mode instead?

No. Chrome profiles separate cookies and history but share the device fingerprint entirely — same canvas hash, same WebGL renderer, same fonts, same screen metrics — and if you are on one network they also share your exit IP. Incognito is weaker still: it discards cookies at the end of the session and changes nothing else. Both solve convenience, not correlation.

How many eBay accounts can I realistically run from one computer?

Technically the limit is memory: each profile is its own browser process, and a machine with 16 GB comfortably holds a handful open at once while storing hundreds on disk. The real limit is operational. Every account needs its own entity, bank account, phone, address, inventory photographs and dispatch process. Most people who try to scale past five or six well-run accounts fail on logistics and paperwork long before the software becomes a constraint.

Do I need a residential proxy for every account, or can they share?

One exit IP per profile. Sharing an exit between two accounts re-links them at the network layer and undoes the browser isolation completely — it is the most common single point of failure in an otherwise careful setup. Residential or mobile, sticky for hours or days, and geographically consistent with the address on the account.

Should I change the fingerprint if I think an account is being watched?

No — that usually makes things worse. Real hardware does not change, so a fingerprint shift on an established account reads as a new device on a known login, which is the signature of a hijacking. Generate a fingerprint once, pin it to the profile, and let it drift only when the browser version legitimately updates.

How long before a new eBay selling account is stable?

Plan for roughly thirty to sixty days of deliberate, small-volume trading: ten-plus completed transactions with tracking, same-day dispatch, fast message replies, no cases opened, and gradual limit increases requested rather than demanded. Accounts that ratchet up slowly reach high limits faster than accounts that push hard in week two, because the fast ones get reviewed and the slow ones get trusted.

Closing thought

The uncomfortable truth about this topic is that the browser is the easy part. A well-built antidetect setup closes the device layer properly and permanently, and it takes an afternoon. The layers that actually end accounts — a shared bank account, a reused return address, the same product photograph on two storefronts, a support ticket sent from the wrong window — are all discipline, and discipline is what separates sellers who run six accounts for three years from sellers who rebuild every quarter.

So build the technical foundation once and correctly: one identity, one profile, one data directory, one coherent fingerprint, one sticky residential exit, one bank account. Then spend your attention on the paperwork and the habits, because that is where the risk lives.

If you want the device layer handled natively rather than bolted on with extensions — per-profile fingerprints applied inside the engine, isolated data directories, per-profile proxies with WebRTC masked to the exit, and team access scoped per person — Dual Login is built for exactly this workload. Set up one profile, run it properly for a month, and see how it feels before you scale.

Run every account like a separate device

Dual Login gives each profile a real fingerprint, its own proxy and sealed storage — free plan, no card required.

More reading

Guides

How to Run Multiple eBay Accounts Safely in 2026

How to Run Multiple eBay Accounts Safely in 2026 Ask ten established eBay sellers whether they run more than one account and at least seven will say yes. One for refurbished electronics. One for the vintage side business that started as a hobby. One for the liquidation pallets they would rather keep away from their main storefront's feedback score. Multiple accounts are normal on eBay — and losing several of them in a single afternoon, because eBay quietl

Guides

Separate IP Address for Each Amazon Account: The 2026 Guide

Separate IP Address for Each Amazon Account: The 2026 Guide Ask anyone who has lost an Amazon seller account to a related-account suspension and they will tell you the same thing: the ban did not arrive because of what they sold. It arrived because Amazon decided two accounts belonged to the same person, and one of those accounts had a problem. The linkage is the risk. And of all the signals Amazon uses to link accounts, the IP address is the first one pe

Guides

How Does Amazon Detect Multiple Accounts? The Full 2026 Breakdown

How Does Amazon Detect Multiple Accounts? The Full 2026 Breakdown Diagram-style illustration showing how Amazon detects multiple accounts through network, fingerprint, payment and behavioral signals Every week, somewhere on a seller forum, the same post appears. "Second account suspended within 48 hours. Different email, different IP, different laptop. How did they know?" The replies are usually a mix of folklore and half-truths. Someone blames cookies. S