Guide schedule5 min read

TCP OS spoofing (anti TCP/IP fingerprinting)

Anti-bot systems don't only look at your IP. They also read how your connection behaves at the TCP/IP level and compare that with the operating system your browser claims to run. When the two disagree, the session looks automated. TCP OS spoofing aligns the network-level signature with your browser profile so both tell the same story.

What TCP/OS fingerprinting actually is

Every operating system implements the TCP/IP stack slightly differently: initial window size, TTL, MSS, window scaling, the presence and ordering of TCP options, timestamp behaviour. Those differences are stable enough that a passive observer can infer the OS from the first few packets of a connection alone, without a single line of JavaScript. The technique is old and well documented — it long predates the anti-bot industry. The result is a second, independent opinion about who you are, formed before your browser sends a single header.

Why a proxy creates an OS mismatch

Almost all proxy infrastructure runs on Linux. When you browse through it, the TCP handshake that reaches the website is produced by that Linux host, not by your machine. So a profile announcing Windows 10 in its User-Agent arrives over a connection whose low-level signature says "Linux server". Nothing in the page content is wrong: the contradiction sits entirely below the application layer — which is exactly what makes it such a useful signal for anyone trying to spot proxies. OS spoofing removes the contradiction by rewriting the TCP/IP characteristics to match the OS your profile claims.

How it works at FRProxy

OS spoofing runs on the proxy itself — nothing to install on your side. You pick the fingerprint from your dashboard or through the API (POST /api/v1/spoof), and the change applies immediately. Available fingerprints: Windows, macOS, Linux, Android and iOS; leaving the field empty disables spoofing, which is the default. The option is enabled on dedicated phone-based proxies — a fingerprint only means something when a single customer controls the connection, so we never enable it on a modem shared between several accounts. One limitation we state plainly: in IPv4, carriers, CGNAT and DPI equipment can normalise TCP options in transit and overwrite part of the spoofed signature. That is a known industry-wide constraint, not something specific to our service. In IPv6 the packet is not rewritten along the path, so the fingerprint stays coherent end to end.

help

FAQ

Does OS spoofing make me undetectable? expand_more
No, and be sceptical of anyone claiming otherwise. It closes one specific inconsistency: the gap between your announced OS and your TCP/IP signature. Detection also weighs your IP reputation, your browser fingerprint (canvas, WebGL, fonts, timezone) and your behaviour. OS spoofing is one layer among several — it removes a reason to be flagged, it does not grant immunity.
My fingerprint test still shows Android — why? expand_more
Because our proxies run on real phones: Android is the genuine signature of the device underneath. When it shows through, the spoofed one did not survive the trip. Some ISPs, carrier-grade NAT, firewalls and DPI systems normalise TCP options in transit and override the spoofed signature — this happens in IPv4, where the carrier rewrites part of the packet. Retry the test over IPv6: the packet is not rewritten along the path, so the fingerprint arrives intact. Also make sure no extra VPN or tunnel sits after the proxy — the test sees the last stack that touched the packet.

Ready to live the French Proxy Experience ?

Real French 4G/5G mobile IPs, on-demand rotation, SMS reception.