Windows TCP/IP Fingerprint on Every Proxy, Free
Every Stat Proxies IP sends a Windows 11 TCP/IP fingerprint: TTL 128, 65535 window, Windows option order, no timestamps. Free on every plan, nothing to configure.
Frequently asked questions
What is a TCP/IP fingerprint?
It is the set of values an operating system puts in the first packet of every TCP connection: the TTL, the window size, the order of the TCP options, whether timestamps are on, and the source port. Each OS uses different defaults, so a website can tell Windows, macOS, and Linux apart from that one packet without running any JavaScript.
Does the Windows TCP/IP fingerprint cost extra?
No. It is included on every IP on every plan at no extra cost, the same way SOCKS5 is.
Do I need to turn it on?
No. Every connection our servers open to a website already carries the Windows fingerprint, over HTTP, HTTPS, and SOCKS5. There is no setting, header, or username change.
Does it change my TLS or browser fingerprint?
No. HTTPS traffic stays encrypted end to end, so your TLS fingerprint (JA3 or JA4), HTTP/2 settings, headers, and JavaScript fingerprint all come from your own client. We change only the TCP and IP layer of the connection between our server and the website.
What if my user agent says Mac or iPhone?
The TCP layer will still say Windows, so a site that compares the two will see a mismatch. For the cleanest result, send a Windows user agent, which is also what most desktop browser traffic on the web looks like.
Does it work with SOCKS5 and UDP?
It applies to every TCP connection, including TCP over SOCKS5. UDP has no TCP handshake, so DNS, WebRTC, and HTTP/3 traffic over SOCKS5 UDP is not affected.
How can I check it?
Send a request through your proxy to https://tls.peet.ws/api/all and read the tcp_syn block. You should see a window of 65535, window scale 8, timestamps false, and the option order mss, nop, wscale, nop, nop, sackOK. The TTL shows as 128 minus the number of hops to their server, usually somewhere between 110 and 125.
Will it get me past Cloudflare or other anti-bot systems?
It removes one signal: a Windows browser arriving on a Linux TCP stack. Anti-bot systems also score your IP history, TLS fingerprint, browser environment, and behavior, and a proxy controls none of those except the IP. Treat it as one less thing that can give you away, not a bypass.