The feature spoofs the proxy’s network fingerprint to match the selected operating system. It is free and available to all customers.
Why this is needed. Anti-fraud systems (p0f, Akamai, Cloudflare, and others) identify a device’s operating system by TCP packet parameters — TTL, MSS, Window Size, and the order of TCP options. If, in a profile-isolated browser, you claim Android but the network stack looks like Windows, that mismatch can trigger a flag. This feature aligns the network layer with what you specify in the browser.
Important: this is a separate masking layer. It does not replace a profile-isolated browser, but complements it — covering the network layer that the browser fingerprint does not.
How to enable it
- Dashboard → “My proxies”.
- For the proxy you need, click the gear icon on the right side of the row.
- Select “TCP Fingerprint”.
- In the window that opens, choose an OS profile from the list.
- Click “Apply”.
The setting is applied on the fly: there’s no need to restart the software or change the connection details.
How to check the result. The same window includes diagnostics — it sends a test request through your proxy and compares what the external service sees with the selected profile. Some individual parameters may differ from the reference values, and that is normal network behavior: see the explanation in the FAQ below.
If the proxy stops responding after selecting a profile
- Open the same window and select “— Native OS (reset profile) —”. If the connection is restored, the issue is with the profile.
- Try another profile from the list: different profiles combine differently with a specific operator network.
- If no profile works, leave Native OS enabled and send us the proxy PID and the profile name — we’ll look into the specific case.
Which proxies support the feature. The profile is assigned to a specific device. If the proxy’s gear menu does not show “TCP Fingerprint”, the feature is not yet available for that device — try switching to another device in the same GEO. Availability depends on the device, not the selected country.
Does the profile affect speed? The spoofing itself works at the packet-header level and does not create noticeable load. But the profile also sets MSS and window size, and these parameters affect how the network transmits data. If speed drops on a specific proxy after enabling a profile, compare it with Native OS mode and, if needed, choose another profile.
Configuring via API. You can also manage the profile programmatically — the command and parameters are described in the “API” section of your dashboard. The proxy identifier in the request is the same number (PID) shown in the first column of the “My proxies” table. An error like proxy_or_proxy_id_required means the identifier was not provided or was passed under a different parameter name: check the request example in the “API” section.
Common questions
Is this the same as the fingerprint in a profile-isolated browser?
No. Browser fingerprinting works inside the browser (JavaScript, Canvas, User-Agent). Ours works at the network-packet level, regardless of the browser. For full masking, use them together.
Will the setting disappear if I change GEO or operator?
No. The profile is automatically transferred to the new device — you won’t lose anything.
MSS shows 1400 instead of 1460 — is that an error?
No. The mobile operator lowers MSS in 4G networks (the PMTUd mechanism, Path MTU Discovery). This is unrelated to our feature. The diagnostics account for this behavior and still show “matched”.
TTL shows 47, but 64 was expected — does that mean it doesn’t work?
No. TTL decreases at each router along the path (natural hop decrement). If there are 17 nodes between you and the checking service, TTL will be 64−17=47. The diagnostics take the number of nodes into account and restore the original value.
Do Android 11 and Android 15 work the same way?
Yes. They have an identical TCP network stack: OS versions differ in the interface, not in network parameters.
Can I revert to the previous state?
Yes. Open the settings window → select “— Native OS (reset profile) —” → apply.
Is this paid?
No. The feature is free for all customers, with no extra charges.
Why MSS is lower than 1460 and whether MTU can be raised to 1500. In cellular networks, packet size is almost always smaller than on wired connections. The operator builds transport on top of tunnels, and each encapsulation layer takes away part of the packet.
Measurements on production ports on September 15, 2026, one port in ten countries: MSS from 1220 to 1460, median 1398, with 1300 and 1400 appearing most often. This corresponds to an MTU of roughly 1260 to 1500.
This is normal mobile-network behavior, not a proxy defect. A site will see exactly the same MSS for any subscriber who connects from a phone. So a reduced MSS does not reveal proxy usage — on the contrary, it confirms a mobile connection.
When this becomes a problem. If a site won’t open or cuts off on large responses, that’s a classic sign that ICMP is being blocked along the path and the endpoints can’t agree on packet size. The fix is to lower MSS on your side, not to raise MTU on ours: limit MSS on the outbound interface or in the tunnel settings to a value that passes through. If the browser profile claims a desktop computer while the network layer looks mobile, align it with a mobile profile, not the other way around.
What you cannot do: raise MTU to 1500 on our side. That is an operator-network parameter, and it is outside our control.