Skip to content
ProxyHub

TCP/IP fingerprint (OS fingerprint): what it is and why it must match your browser

Published · 3 min read

Your browser states its operating system in the user agent, but network packets tell their own story. If the two don't match, anti-fraud systems notice. It's one of the most underrated signals among proxy users.

What a TCP/IP fingerprint is

When a device opens a connection, the first packet (the SYN) carries parameters that the operating system sets in its own way. Nobody picks them by hand: they're defaults of Windows, macOS, iOS, Linux, Android and so on. Together they form a fairly recognisable fingerprint.

This is called passive OS fingerprinting: the site doesn't need to do anything special, it just looks at the packets it receives. Open-source tools such as p0f have done this for years, and many commercial anti-fraud systems build it in.

What a packet reveals

ParameterWhat it isExample
Initial TTLHow many router hops the packet may takeWindows starts at 128; Linux, Android, macOS and iOS at 64
TCP windowHow much data the system accepts before an acknowledgementDifferent values and scaling per system
MSSMaximum segment sizeDepends on network and system
TCP options and orderSupported features and their sequenceWindows and Linux list them in a different order
TCP timestampsTime stamp in packetsWindows normally doesn't send it, Linux and macOS do

No single parameter is decisive, but together they let a site guess the operating system quite accurately.

Why it matters with a proxy

With a proxy the site doesn't receive packets from your computer: it receives them from the device opening the connection for you. With a mobile proxy that's the smartphone. So the site sees:

  • a user agent saying, for example, “Windows 11, Chrome”;
  • a TCP/IP fingerprint saying something else — the smartphone's system (Android).

For a real user the two always match. A mismatch doesn't necessarily mean a block, but it raises the risk score: more captchas, extra checks, stricter limits.

How to make them match

The fix is to send packets with the fingerprint of the system your browser claims. With ProxyHub you choose it on the proxy page in the client area:

  • Windows 10/11, macOS, iOS, FreeBSD 9 and Nintendo: the proxy mimics that system's fingerprint.
  • None: keeps the smartphone's original (Android) fingerprint, useful when your browser profile emulates a phone.
The rule is simple: Windows antidetect profile → Windows fingerprint; macOS profile → macOS fingerprint; iPhone profile → iOS fingerprint.

In antidetect browsers the operating system is set in the profile: choose the same on both sides. Instructions for the most popular tools are in the setup guides, and what these tools are is explained in Antidetect browsers.

How to check it

There are test sites that show the operating system inferred from TCP packets next to the one your browser declares. Open them through the proxy and check the two values match. How to test a proxy lists every check to run before using a profile.

Frequently asked questions

Is the TCP/IP fingerprint the same as the browser fingerprint?

No. The browser fingerprint (canvas, fonts, WebGL) comes from the browser; the TCP/IP fingerprint comes from network packets. They're two different layers and must be consistent with each other.

Does a VPN fix this?

No: with a VPN the packets to the site are created by the VPN server, usually Linux. The mismatch remains unless the service lets you choose.

Which fingerprint should I pick?

The one matching the operating system your browser or profile declares. If you use a regular browser on Windows, pick Windows.

Try a 5G mobile proxy

Dedicated smartphone, unlimited traffic, real carrier IPs. Live in minutes.

See plans

Read next

All articles