What your connection gives away before a page runs a single script: your IP address, the TLS handshake,
HTTP/2 settings and the order of your headers. Sites use these to tell browsers apart even when the user agent lies.
What the server sees
Connection
IP address
216.73.217.10•••.•••.•••.•••
Protocol
HTTP/2.0
TLS version
TLS 1.3
Cipher
TLS_AES_128_GCM_SHA256
ALPN
h2
Who does it look like?
User agent says
Unknown
TLS handshake says
Other
HTTP/2 says
Other
Chrome and Safari add random "GREASE" values to the handshake, Firefox never does. Each engine also sends HTTP/2 pseudo-headers in its own order.
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
accept-encoding
gzip, br, zstd, deflate
What your browser shows
These tests run only in your browser. Their results are never sent to the server.
WebRTC
Public IP seen by WebRTC
Testing…
Local addresses
Testing…
Result
Testing…
A VPN or proxy that WebRTC bypasses shows up here as a public IP different from the one above. Browsers hide local addresses behind random .local names.
API
The same data as JSON, for scripts and for Spitfire's about:fingerprint page. CORS is open, and each IP gets 30 requests per minute.