The wire fingerprints traffic claiming this operator's crawlers presented, split by whether the claim is consistent with the network the operator publishes as its own. Meta documents its crawler User-Agents and a network retrieval procedure — AS32934 route objects it maintains in the RADb registry — but no crawler-specific IP list, so membership confirms operator origin, while a claim from outside is unverified: an anomaly, not proof of spoofing.
Claims in window
Same adjudication as the stats page, under this operator's published channel: a claim from inside the network the operator publishes as its own is consistent with operator origin; one from outside is unverified — inconsistent with the published network, but not a confirmed fake, because the operator does not state that set is exhaustive crawler egress. A claim from inside a different operator's published crawler range is a strong impersonation signal. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.
observations
sources
consistent
outside network
foreign crawler range
unconfirmed rate
15423
1363
1363
0
0
0.0%
Fingerprints presented by confirmed traffic
The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels (here: membership of the operator's published network). A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.