The wire fingerprints traffic claiming to be this crawler presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.
Claims in window
Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.
observations
sources
legit
spoofed
spoof rate
20
9
5
4
44.4%
Fingerprints presented by confirmed traffic
The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels. A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.
3:100;4:65536;2:0|1048510465|0|m,s,a,pMatch?Exact match in Thumbprint's published controlled catalog captures: curl 8.13.0, curl 8.18.0, curl 8.21.0, +7 more.The fingerprint page shows the full measured match list. More on the catalog.
The impostor inventory: the highest-volume fingerprints wearing this operator's User-Agent that no operator-published channel confirms, per signal. A Match pill here shows known clients measured producing the same fingerprint an impostor presents.