Applebot

The wire fingerprints traffic claiming to be this crawler presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.

Claims in window

Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.

observationssourceslegitspoofedspoof rate
26357657510.2%

Fingerprints presented by confirmed traffic

The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels. A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.

TLS ClientHello (JA4)

fingerprintobservations
t13d9912h1_ee3966d44962_c50a3655fff1 620

HTTP request (JA4H)

fingerprintobservations
ge20nn030000_6dac75bd47eb_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: python-httpx 0.28.1.The fingerprint page shows the full measured match list. More on the catalog. 620

HTTP/2 frames (Akamai)

fingerprintobservations
1:65536;2:0;4:2097152;5:131072;6:524288|5177345|0|m,s,a,p 620

TCP SYN (JA4T)

fingerprintobservations
62727_2-4-8-1-3_8365_7 620

TCP SYN (p0f)

fingerprintobservations
4:111+17:0:8365:62727,7:mss,sok,ts,nop,ws:df,id+:0 423
4:112+16:0:8365:62727,7:mss,sok,ts,nop,ws:df,id+:0 192
4:109+19:0:8365:62727,7:mss,sok,ts,nop,ws:df,id+:0 5

Fingerprints presented by unconfirmed claims

The impostor inventory: the highest-volume fingerprints wearing this operator's User-Agent that no operator-published channel confirms, per signal. A Match pill here shows known clients measured producing the same fingerprint an impostor presents.

TLS ClientHello (JA4)

fingerprintobservations
t13d131200_f57a46bbacb6_9249cab70c77 3

HTTP request (JA4H)

fingerprintobservations
ge11nr05enus_f3bb7aa45ec4_000000000000_000000000000 3

TCP SYN (JA4T)

fingerprintobservations
42600_2-4-8-1-3_1420_9 3

TCP SYN (p0f)

fingerprintobservations
4:58+6:0:1420:mss*30,9:mss,sok,ts,nop,ws:df,id+:0 3