TCP fingerprint test

Observe initial TCP SYN characteristics

Inspect selected characteristics of the initial IPv4 TCP SYN that reached MyLeaks and see how the current network path may have influenced them.

Live result

Current passive TCP observation

JavaScript required

JavaScript is required to establish and correlate the qualifying HTTPS connection.

Not observed means that no usable TCP result was available for this connection.

MyLeaks TCP fingerprint

JavaScript required

Algorithm: myleaks-tcp-v1

Initial SYN summary

JavaScript required

Technical details
Availability reason
JavaScript required
Canonical
JavaScript required
Raw TCP window
JavaScript required
MSS
JavaScript required
Window scale
JavaScript required
SACK permitted
JavaScript required
Timestamp option
JavaScript required
TCP Fast Open
JavaScript required
ECE/CWR state
JavaScript required
IPv4 DF
JavaScript required
TCP option order
JavaScript required
Duplicate known options
JavaScript required
Observed TTL
JavaScript required
Estimated initial TTL
JavaScript required
Estimated hops
JavaScript required
JavaScript is required to run the live TCP test.

What this test measures

MyLeaks observes selected characteristics of the initial IPv4 TCP SYN, including window, MSS, window scale, option presence and order, ECN flags, and IPv4 DF.

How it works

The test reads the initial TCP connection characteristics and builds a versioned summary from stable fields. See Methodology for calculation details.

What the result means

The result summarizes selected initial SYN characteristics received by MyLeaks. It is MyLeaks-defined and is not JA4T. The hash excludes the connection tuple, observed TTL, estimated initial TTL, and estimated hop count.

Limitations