Network stack

TCP/IP fingerprint test

See the network signals your connection reveals. Start a test when you are ready.

Your result

Ready to check your connection

Start the test to capture a fresh network observation.

Ready
Estimated operating system family

Not checked

Confidence—

A VPN, proxy or router can change these signals. This is an estimate, not an exact device identification.

View packet details ↓

Behind the result

Open the measurements or evidence you want to inspect.

TCP packet measurements & signature
Localtonet signatureNot checkedThe Localtonet lts1 signature is not JA4T or p0f.
Address family—
TTL—
Window size—

TCP option order

Not checked
Classification evidence & connection matching
Matched profile
—
Connection matching
—
  • Evidence will appear after the check.

What does this tell you?

Recognizable network signals

Operating systems choose TCP settings such as window size, maximum segment size and option order. Their combination can suggest a broad system family.

Your connection can change them

A VPN, proxy, firewall or router may alter these settings. The result can describe an intermediary rather than your device.

Why is the result unavailable or inconclusive?

The collector needs to match a fresh connection to its packet metadata. Connection reuse, filtering, rate limits or several simultaneous connections can prevent a reliable match. Run the check again to request a new observation.

What do TTL, MSS and option order mean?

TTL limits how many routers a packet can pass. MSS is the largest TCP payload the sender wants to receive. TCP options negotiate features such as window scaling and timestamps. The combination is more useful than any one value.

Does this scan my device or identify me?

Your browser makes an HTTPS request; the collector observes that connection’s initial packet. It does not scan your ports or identify you by name. Public results omit the source address, source port and raw TCP timestamps.

support