The wire fingerprints traffic claiming to be this crawler presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.
Claims in window
Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.
observations
sources
legit
spoofed
spoof rate
334
35
28
7
20.0%
Fingerprints presented by confirmed traffic
The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels. A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.
The impostor inventory: the highest-volume fingerprints wearing this operator's User-Agent that no operator-published channel confirms, per signal. A Match pill here shows known clients measured producing the same fingerprint an impostor presents.
TLS ClientHello (JA4)
fingerprint
observations
t13d1516h2_8daaf6152771_d8a2da3f94cdMatch?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog.