Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.
| Protocol | t (TLS over TCP) |
| TLS version | 13 |
| SNI | d (domain) |
| Cipher count | 11 |
| Extension count | 10 |
| ALPN | h2 |
| Ciphers | 002f, 0035, 009d, 1301, 1302, 1303, c013, c014, c02f, c030, cca8 |
| Extensions | 000a, 000b, 000d, 0017, 002b, 002d, 0033, ff01 |
| Signature algorithms | 0403, 0804, 0401, 0503, 0805, 0501, 0806, 0601 |
| JA4_r | t13d1110h2_002f,0035,009d,1301,1302,1303,c013,c014,c02f,c030,cca8_000a,000b,000d,0017,002b,002d,0033,ff01_0403,0804,0401,0503,0805,0501,0806,0601 |
| JA4_o (sample) | t13d1110h2_e68653f21539_a0e41e8e5673 |
| JA4_ro (sample) | t13d1110h2_1301,1302,1303,cca8,009d,0035,c013,002f,c02f,c030,c014_0010,0000,0017,0033,000b,000d,ff01,002d,002b,000a_0403,0804,0401,0503,0805,0501,0806,0601 |
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.