Bingbot

The wire fingerprints traffic claiming to be this crawler presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.

Claims in window

Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.

observationssourceslegitspoofedspoof rate
54400.0%

Fingerprints presented by confirmed traffic

The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels. A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.

TLS ClientHello (JA4)

fingerprintobservations
t13d2013h2_2b729b4bf6f3_e24568c0d440 6
t13d2212h2_231e334592e8_36bf25f296df 2

HTTP request (JA4H)

fingerprintobservations
ge20nn060000_0c07ec02b430_000000000000_000000000000 6
ge20nn040000_200b94e8daef_000000000000_000000000000 1
ge20nn040000_31537f9be9e0_000000000000_000000000000 1

HTTP/2 frames (Akamai)

fingerprintobservations
2:0;4:10485760|10420225|0|m,p,a,s 6
2:0;4:65535|67043329|0|m,s,a,p 2

TCP SYN (JA4T)

fingerprintobservations
64240_2-1-1-4_1440_00 6
64240_2-1-3-1-1-4_1440_8 2

TCP SYN (p0f)

fingerprintobservations
4:114+14:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 3
4:112+16:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 2
4:114+14:0:1440:mss*44,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:0 2
4:113+15:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 1