Perplexity-User

The wire fingerprints traffic claiming to be this fetcher presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.

Claims in window

Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.

observationssourceslegitspoofedspoof rate
8827027100.0%

Fingerprints presented by unconfirmed claims

The impostor inventory: the highest-volume fingerprints wearing this operator's User-Agent that no operator-published channel confirms, per signal. A Match pill here shows known clients measured producing the same fingerprint an impostor presents.

TLS ClientHello (JA4)

fingerprintobservations
t13d131200_f57a46bbacb6_9249cab70c77 67
t13d131300_f57a46bbacb6_1bd98dace775 18
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog. 3

HTTP request (JA4H)

fingerprintobservations
ge11nr05enus_f3bb7aa45ec4_000000000000_000000000000 54
ge11nn05enus_f3bb7aa45ec4_000000000000_000000000000 21
ge11nr060000_6f1c3d56a901_000000000000_000000000000 6
ge11nr040000_e1d2031bdfea_000000000000_000000000000 3
ge11nr030000_cd680697de12_000000000000_000000000000 1
ge20nn050000_857b5fa3405d_000000000000_000000000000 1
ge20nn050000_bb384e635ab6_000000000000_000000000000 1
po20nn040000_389b5b1db9ed_000000000000_000000000000 1

HTTP/2 frames (Akamai)

fingerprintobservations
2:0;4:4194304;5:16384;6:262144;1:65536|1073741824|0|a,m,p,s 3

TCP SYN (JA4T)

fingerprintobservations
42600_2-4-8-1-3_1420_9 85
65320_2-4-8-1-3_1420_10 3

TCP SYN (p0f)

fingerprintobservations
4:58+6:0:1420:mss*30,9:mss,sok,ts,nop,ws:df,id+:0 81
4:58+6:0:1420:mss*46,10:mss,sok,ts,nop,ws:df,id+:0 3
4:51+13:0:1420:mss*30,9:mss,sok,ts,nop,ws:df,id+:0 2
4:50+14:0:1420:mss*30,9:mss,sok,ts,nop,ws:df,id+:0 1
4:55+9:0:1420:mss*30,9:mss,sok,ts,nop,ws:df,id+:0 1