TCP/IP fingerprint (OS fingerprint): what it is and why it must match your browser
Published · 3 min read
Your browser states its operating system in the user agent, but network packets tell their own story. If the two don't match, anti-fraud systems notice. It's one of the most underrated signals among proxy users.
What a TCP/IP fingerprint is
When a device opens a connection, the first packet (the SYN) carries parameters that the operating system sets in its own way. Nobody picks them by hand: they're defaults of Windows, macOS, iOS, Linux, Android and so on. Together they form a fairly recognisable fingerprint.
This is called passive OS fingerprinting: the site doesn't need to do anything special, it just looks at the packets it receives. Open-source tools such as p0f have done this for years, and many commercial anti-fraud systems build it in.
What a packet reveals
| Parameter | What it is | Example |
|---|---|---|
| Initial TTL | How many router hops the packet may take | Windows starts at 128; Linux, Android, macOS and iOS at 64 |
| TCP window | How much data the system accepts before an acknowledgement | Different values and scaling per system |
| MSS | Maximum segment size | Depends on network and system |
| TCP options and order | Supported features and their sequence | Windows and Linux list them in a different order |
| TCP timestamps | Time stamp in packets | Windows normally doesn't send it, Linux and macOS do |
No single parameter is decisive, but together they let a site guess the operating system quite accurately.
Why it matters with a proxy
With a proxy the site doesn't receive packets from your computer: it receives them from the device opening the connection for you. With a mobile proxy that's the smartphone. So the site sees:
- a user agent saying, for example, “Windows 11, Chrome”;
- a TCP/IP fingerprint saying something else — the smartphone's system (Android).
For a real user the two always match. A mismatch doesn't necessarily mean a block, but it raises the risk score: more captchas, extra checks, stricter limits.
How to make them match
The fix is to send packets with the fingerprint of the system your browser claims. With ProxyHub you choose it on the proxy page in the client area:
- Windows 10/11, macOS, iOS, FreeBSD 9 and Nintendo: the proxy mimics that system's fingerprint.
- None: keeps the smartphone's original (Android) fingerprint, useful when your browser profile emulates a phone.
In antidetect browsers the operating system is set in the profile: choose the same on both sides. Instructions for the most popular tools are in the setup guides, and what these tools are is explained in Antidetect browsers.
How to check it
There are test sites that show the operating system inferred from TCP packets next to the one your browser declares. Open them through the proxy and check the two values match. How to test a proxy lists every check to run before using a profile.
Frequently asked questions
Is the TCP/IP fingerprint the same as the browser fingerprint?
No. The browser fingerprint (canvas, fonts, WebGL) comes from the browser; the TCP/IP fingerprint comes from network packets. They're two different layers and must be consistent with each other.
Does a VPN fix this?
No: with a VPN the packets to the site are created by the VPN server, usually Linux. The mismatch remains unless the service lets you choose.
Which fingerprint should I pick?
The one matching the operating system your browser or profile declares. If you use a regular browser on Windows, pick Windows.
Try a 5G mobile proxy
Dedicated smartphone, unlimited traffic, real carrier IPs. Live in minutes.
See plans