OS fingerprint spoofing on ISP and datacenter proxies
OS fingerprint spoofing makes a Proxya ISP or datacenter proxy open its TCP connections the way Windows, macOS or Android does, instead of the way the Linux server underneath it does. Five profiles come with every ISP and datacenter order at no extra cost. You can check the result yourself in a minute.
- Available on
- ISP and datacenter proxies
- Profiles
- Windows 11 (Chrome, Edge, Firefox), macOS (Chrome), Android 14 (Chrome)
- Price
- Included, switching is free
- What changes
- Initial TTL, TCP window, window scale, option order, timestamps
- What stays
- IP address, ASN, TLS fingerprint, browser fingerprint
- Not with
- IP whitelist (passwordless) connections
What an OS fingerprint is
Every TCP connection starts with a SYN packet, and the operating system fills in its fields: the initial TTL, the window size, the maximum segment size, the window scale and the order of the TCP options. Windows, macOS, Linux and Android each fill them differently.
A server can read these values without sending anything back, which is why the method is called passive OS fingerprinting. p0f is the best-known tool for it, and many anti-bot and fraud systems run something similar on the first packet of every visit.
The browser has no say in any of this. The kernel builds the packet, so JavaScript, extensions and antidetect browsers cannot change it.
Why a proxy shows the wrong operating system
Through a proxy, the website receives a TCP connection from the proxy server, not from your device. ISP and datacenter proxies run on Linux servers. A browser that says Windows 11 in its User-Agent therefore arrives in packets that say Linux, and a site that compares the two sees a contradiction ordinary home users almost never produce.
Our anonymity check stored 136 reports with a packet reading between 8 September and 8 October 2026. In 67 of them the operating system in the packets did not match the one the browser claimed. The most common case, 43 reports, was a Windows browser over Linux packets. These are people who chose to test their own connection, many of them through a proxy or VPN, so the share describes proxy users rather than the internet at large.
What each profile changes, measured
On 8 October 2026 we switched a Proxya datacenter proxy in Germany through every profile and read its first packet twice: with the server behind our anonymity check and with the independent classifier at incolumitas.com. An ISP proxy in the United States gave the same values.
| Profile | Initial TTL | Window | Scale | Timestamps | Option order | Our check reads | incolumitas reads |
|---|---|---|---|---|---|---|---|
| No profile (the server's own Linux) | 64 | 64240 | 8 | on | MSS SACK TS NOP WS | Linux | Linux |
| Windows 11 (Chrome, Edge or Firefox) | 128 | 64240 | 8 | off | MSS NOP WS NOP NOP SACK | Windows 10/11 | Windows |
| macOS (Chrome) | 64 | 65535 | 6 | on | MSS NOP WS NOP NOP TS SACK EOL | macOS / iOS | Mac OS |
| Android 14 (Chrome) | 64 | 65535 | 8 | on | MSS SACK TS NOP WS | Linux | Linux |
- The three Windows profiles produce identical packets. TCP carries no browser name, so picking Chrome, Edge or Firefox only keeps the label in line with your setup.
- Android runs the Linux kernel, and a real Android phone reads as Linux at this level too. The profile sets the Android window size, and our check treats an Android browser over these packets as consistent.
- Initial TTL is the value a packet leaves the proxy with. It drops by one at every router on the way, so the readings arrived as 55 and 119 from Germany and as 52 and 116 from the United States. The maximum segment size stayed at 1460 in every profile.
When OS fingerprint spoofing makes sense
The feature keeps a connection consistent with the device it describes. These are the jobs customers use it for.
Ad verification and brand protection
Some ad networks and affiliate pages show a clean version to traffic they recognise as a proxy. Checking what a real Windows or Android visitor is served needs a connection that does not announce the proxy in its first packet.
Testing your own detection
Fraud and bot teams need traffic with a known fingerprint. With a fixed profile they can see which of their rules fire on a consistent visitor and which only catch the obvious mismatch.
Browser profiles that describe one device
Antidetect browsers, Proxya Anty among them, make the browser report a chosen system. With spoofing on, the network layer reports the same system instead of contradicting the profile.
Content and prices that depend on the device
Retail and travel sites can serve different pages to desktop and mobile systems. A matching fingerprint keeps a Linux signal from skewing the measurement.
Spoofing does not make a prohibited use allowed. Fraud, account takeover, payment abuse and breaking a site's terms stay banned by the Acceptable Use Policy, whatever profile an order runs. Read the Acceptable Use Policy
How to turn it on
- 1
Open the order
In the dashboard go to My orders and open an ISP or datacenter order.
- 2
Pick a profile
The OS fingerprint spoofing card lists the five profiles. Choose one and press Apply. The profile covers every proxy in the order.
- 3
Connect with a password
Spoofing works on connections that log in with a username and password. If the order has IPs on its whitelist, the dashboard asks you to clear them first.
The same card switches profiles or turns spoofing off at any time. In the test above we waited 15 seconds after each switch, and every reading already showed the new profile.
Check the result yourself
Connect your browser through the proxy and open the anonymity check. It reads the first packet of your connection and puts the operating system it finds next to the one your browser reports. Without a profile, a Windows browser on a Proxya datacenter proxy shows Linux packets and a mismatch. With the Windows 11 profile both sides read Windows.
For a second opinion, incolumitas.com runs an independent TCP/IP classifier that gave the same answers in our test.
What OS fingerprint spoofing does not change
- The IP address and its owner
- A datacenter address still belongs to a hosting network, and IP databases say so. ISP addresses are registered to consumer providers, which is why they suit sign-ins better.
- The TLS fingerprint
- The TLS handshake (JA3, JA4) comes from your browser and passes through the proxy untouched.
- The browser fingerprint
- Canvas, WebGL, fonts and screen size are reported by the browser. That is the job of an antidetect browser.
- Other proxy types
- Residential and MTProto proxies do not have the setting. Mobile devices have their own OS option with different coverage, described on the mobile page.
- Passwordless connections
- Traffic authorised by an IP whitelist skips the spoofing layer, so the dashboard does not allow both on one order.
OS fingerprint spoofing questions
What people ask before they turn it on.
No. Every Proxya ISP and datacenter order includes it with all five profiles, and switching between them is free.
Windows 11 (offered with Chrome, Edge or Firefox in the profile name), macOS with Chrome and Android 14 with Chrome. There is no iOS profile. Without a profile the proxy sends the Linux packets of its own server.
No. An antidetect browser changes what the browser reports about itself, from the User-Agent to canvas and WebGL. OS fingerprint spoofing changes the TCP packets the proxy server sends. They cover different layers, and both should name the same system.
The one that matches the User-Agent of the browser or app behind the proxy. A Windows browser needs a Windows profile and an Android app needs the Android one. A profile applies to the whole order, so keep one system per order if your tool rotates User-Agents.
Connections authorised by IP skip the layer that rewrites the packets. The dashboard keeps the two apart: clear the whitelist on the order to turn spoofing on, or turn spoofing off to use the whitelist.
Open the anonymity check through the proxy. It shows the operating system your packets reveal next to the one your browser claims and flags a mismatch when they disagree.

