Skip to content
Guides

TLS Fingerprinting Explained: JA3, JA4 and Why Your Scraper Is Blocked Before It Sends a Request

TLS fingerprinting identifies a client by the way it opens an encrypted connection. The first message of every TLS handshake, the ClientHello, lists the protocol versions, cipher suites and extensions the client supports, in an order specific to each TLS library. JA3 and its successor JA4 turn that message into a short fingerprint. A default Python or Node HTTP client produces a fingerprint no browser has, so a site can block it before reading a single header. A proxy does not change this, because the TLS handshake runs end to end through the tunnel.

seamless Team10 min readSeptember 28, 2026
  • tls fingerprinting
  • ja3
  • ja4
  • web scraping
  • detection
Two plugs with identical housings approaching a port, one with a subtly different crimson pin pattern left unseated

How the fingerprint is built

Every HTTPS connection starts with a ClientHello. It is sent in the clear, before encryption begins, and it contains the client's supported TLS versions, cipher suites, extensions, elliptic curves and more. Browsers, OpenSSL-based libraries and Go's TLS stack all fill these lists differently, so the message itself identifies the software that sent it.

JA3JA4
Introduced2017, Salesforce2023, FoxIO
InputVersion, ciphers, extensions, curves, point formatsSimilar fields, with extensions sorted, plus ALPN and SNI
OutputMD5 hashReadable prefix plus truncated hashes
Stable for modern Chrome?No — Chrome randomises extension orderYes — sorting removes the randomness

Chrome started randomising the order of TLS extensions in 2023, which gave the same browser many different JA3 hashes and made JA3 far less useful. JA4 sorts the extensions before hashing, so it stays stable, and its readable prefix — protocol, TLS version, number of ciphers and extensions, ALPN — can be matched partially.

Why proxies do not help

For an HTTPS target, your client asks the proxy to open a tunnel with CONNECT, then performs the TLS handshake with the website through that tunnel. The proxy only moves bytes. The website sees the proxy's IP and your ClientHello. A pool of a million clean residential IPs all presenting the python-requests TLS signature looks like one very large bot.

If requests fail instantly with 403 on a site behind a major bot-management product, while the same URL loads in a normal browser on the same exit, the TLS or HTTP/2 fingerprint is the first thing to test — before blaming the IP.

HTTP/2 fingerprinting

The same idea applies one layer up. HTTP/2 clients send settings, window sizes, priorities and header order at the start of a connection, and these differ between browsers and libraries too. Many HTTP libraries still default to HTTP/1.1, which is itself a signal on sites where every real browser uses HTTP/2 or HTTP/3.

What actually changes your TLS fingerprint

ApproachEffectTrade-off
Real browser (Playwright, Puppeteer)Genuine browser TLS and HTTP/2Heavier, slower, more bandwidth
Browser-impersonating HTTP clientMimics a specific browser's ClientHelloMust track browser updates
Changing cipher lists by handProduces a new, unusual fingerprintRarely matches any real browser
Changing proxy or IPNo effect on TLS fingerprint—

In Python, curl_cffi can impersonate recent Chrome, Safari and Firefox handshakes while keeping a requests-like API:

python
from curl_cffi import requests

proxy = "http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT"
r = requests.get(
    "https://example.com",
    impersonate="chrome",
    proxies={"http": proxy, "https": proxy},
    timeout=30,
)
print(r.status_code)
The proxy supplies the IP; impersonate supplies a browser-shaped handshake. You need both on strict targets.

Keep the rest of the request consistent with the browser you impersonate: a Chrome handshake with a Firefox user agent, or with headers in an order no browser sends, contradicts itself. The broader picture of device-side signals is in what is browser fingerprinting.

Clean exits for a clean handshake

Once the client looks like a browser, the IP is the next signal. Residential from €1.20/GB with sticky sessions; ISP from €1.80/IP.

See residential proxies

Who uses TLS fingerprints

Bot-management products from the large CDNs expose JA3 and JA4 values to their detection models and, on higher tiers, to site owners' own rules. Rate limits can be counted per JA4 fingerprint instead of per IP, which is why rotating IPs sometimes does nothing against a limit — see Cloudflare 1015. Security teams also use them to spot malware and unusual clients on their own networks.

Sources

Frequently asked questions

What is TLS fingerprinting?

It is a way to identify the software making an HTTPS connection from the first message of the TLS handshake, which lists the client's supported versions, ciphers and extensions in a library-specific way.

What is the difference between JA3 and JA4?

Both turn the TLS ClientHello into a fingerprint. JA3 hashes the fields in the order they are sent, which broke when Chrome began randomising extension order. JA4 sorts extensions first, adds ALPN and SNI information and uses a partly readable format, so it stays stable.

Does a proxy change my TLS fingerprint?

No. For HTTPS the proxy only tunnels the connection, and the TLS handshake takes place between your client and the website. The site sees the proxy's IP but your client's fingerprint.

Why is Python requests blocked when a browser is not?

Python requests uses OpenSSL defaults that produce a TLS and HTTP fingerprint no browser has, so bot-detection systems can identify it before reading any headers. A browser-impersonating client or a real browser avoids this.

How do I change my TLS fingerprint?

Use a real browser through Playwright or Puppeteer, or a client that impersonates a browser handshake, such as curl_cffi in Python. Changing individual ciphers by hand usually creates a new, unusual fingerprint instead.

SE
seamless Team
Proxy infrastructure

The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.

Ready to try seamless proxies?

Residential, ISP and datacenter proxies with no data expiry.

Browse Plans