> ## Documentation Index
> Fetch the complete documentation index at: https://docs.statproxies.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Windows TCP/IP Fingerprint

> Every Stat Proxies IP sends a Windows 11 TCP/IP fingerprint on every connection. What that means, what it covers, and how to check it.

Every connection from every Stat Proxies IP carries the TCP/IP fingerprint of a Windows 11 PC. It is included free on every plan, it works over HTTP, HTTPS, and SOCKS5, and there is nothing to turn on.

## What it is

The first packet of every TCP connection (the SYN) carries values that depend on the operating system that sent it: the TTL, the window size, the order of the TCP options, whether timestamps are on, and the source port. A website can read those values and tell Windows, macOS, and Linux apart.

Through a proxy, the website sees the proxy server's packets, not yours. Proxy servers usually run Linux, so proxy traffic usually reads as Linux even when your browser says Windows. Our servers send Windows values instead.

| Field | Stock Linux server | Stat Proxies | Windows 11 PC |
| - | - | - | - |
| TTL sent | 64 | 128 | 128 |
| SYN window size | 64240 | 65535 | 65535 |
| Window scale | 7 | 8 | 8 |
| TCP option order | mss, sackOK, ts, nop, wscale | mss, nop, wscale, nop, nop, sackOK | mss, nop, wscale, nop, nop, sackOK |
| TCP timestamps | On | Off | Off |
| Source ports | 32768-60999 | 49152-65535 | 49152-65535 |

## What it covers

<CardGroup cols={2}>
  <Card title="Windows fingerprint" icon="check">
    Every TCP connection our servers open to a website: HTTP and HTTPS proxy traffic, and TCP over SOCKS5 (WebSockets, SSH, email, and so on). Every IP, every plan.
  </Card>

  <Card title="Comes from your client" icon="laptop">
    Your TLS fingerprint (JA3, JA4), HTTP/2 settings, headers, user agent, and browser fingerprint. UDP over SOCKS5 has no TCP handshake, so it has no TCP fingerprint.
  </Card>
</CardGroup>

<Tip>
  If your user agent says macOS, iPhone, or Android, the TCP layer will still say Windows. Send a Windows user agent for the cleanest match.
</Tip>

## Check it

[tls.peet.ws](https://tls.peet.ws) echoes back the fingerprint of whatever connects to it. Send one request through your proxy and read `tcpip.tcp_syn`. Use the host, port, username, and password from your dashboard.

<Tabs>
  <Tab title="cURL">
    ```bash theme={null}
    curl -s -x http://USERNAME:PASSWORD@HOST:PORT \
      https://tls.peet.ws/api/all | jq .tcpip.tcp_syn
    ```
  </Tab>

  <Tab title="Python">
    ```python theme={null}
    import requests

    proxy = "http://USERNAME:PASSWORD@HOST:PORT"
    r = requests.get(
        "https://tls.peet.ws/api/all",
        proxies={"http": proxy, "https": proxy},
        timeout=20,
    )
    syn = r.json()["tcpip"]["tcp_syn"]
    print(syn["ttl"], syn["window"], syn["window_scale"], syn["timestamps"], syn["option_order"])
    ```
  </Tab>
</Tabs>

You should see:

| Field | Expected value |
| - | - |
| `ttl` | About 110 to 125 (128 minus one per network hop) |
| `window` | `65535` |
| `window_scale` | `8` |
| `timestamps` | `false` |
| `option_order` | `mss,nop,wscale,nop,nop,sackOK` |
| `src_port` | 49152 or higher |

If you see a TTL under 64 or `timestamps: true`, the request did not go through a Stat Proxies IP. Check that your client is actually using the proxy, then [contact support](mailto:support@statproxies.com) if it still looks wrong.

## FAQ

<AccordionGroup>
  <Accordion title="Does it cost extra?">
    No. It is included on every IP on every plan, the same as SOCKS5.
  </Accordion>

  <Accordion title="Do I need to change my username, port, or headers?">
    No. Every connection already carries the Windows fingerprint.
  </Accordion>

  <Accordion title="Does it add latency?">
    No measurable latency. The values are set inside our servers' network stack as each connection opens.
  </Accordion>

  <Accordion title="Will it get me past Cloudflare or other anti-bot systems?">
    It removes one signal, a Windows browser arriving on a Linux TCP stack. Anti-bot systems also score IP history, TLS fingerprint, browser environment, and behavior. See [Blocked Requests](/articles/blocked-requests) for the rest.
  </Accordion>
</AccordionGroup>

For background, read [What is TCP/IP fingerprinting?](https://www.statproxies.com/blog/what-is-tcp-ip-fingerprinting) on our blog.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.