← back to blog

What a Fingerprint Checker Site Really Measures

Run any browser through a fingerprint checker and you’ll get a page full of green checkmarks, a uniqueness score, and maybe a percentage that claims to represent how identifiable your session is. It looks authoritative. It isn’t a verdict. It’s a snapshot of a handful of signals that a script running in your browser was able to read at that exact moment, compared against a database of other sessions the site has seen before.

I run proxy infrastructure and cloud-based phones for multi-accounting work, and I test anti-detect browsers against these checker sites constantly, because the checker is the first thing anyone reaches for when they want to know if a profile “looks clean.” It’s a useful diagnostic. It is not proof that a platform’s own detection system will treat the profile the same way. Those are two different systems reading two different sets of signals, and conflating them is where a lot of operators get burned.

The signals a checker site can actually see

A fingerprint checker runs entirely in JavaScript (sometimes with a bit of CSS) inside your browser tab. It can only read what the browser exposes through its APIs. That’s the whole game: every anti-detect browser is trying to control what those APIs return, and every checker site is trying to read them and compare the result against known patterns.

The signals fall into a few buckets:

  • Rendering signals – canvas, WebGL, and font rendering, which vary based on your GPU, driver, and OS text rendering engine.
  • Hardware and environment signals – screen resolution, color depth, timezone, language, CPU core count, device memory.
  • Software signals – user agent string, installed plugins, browser build details, and dozens of small API quirks that differ between Chrome, Firefox, and their forks.
  • Network signals – IP address, WebRTC-leaked local/public IPs, and in some cases TLS handshake characteristics.
  • Behavioral signals – mouse movement, typing cadence, scroll patterns. Checker sites rarely score this one well because it needs real interaction, not a page load.

A checker site scores maybe fifteen to twenty of these. A platform doing real anti-fraud work at scale, like a social network or a marketplace, has access to all of the above plus your account history, payment signals, device graph across other accounts, and behavioral data over weeks, not seconds. That gap is the whole reason a clean checker report doesn’t translate into a safe account.

Canvas and WebGL: the two everyone talks about

Canvas fingerprinting works by asking your browser to draw a hidden image or piece of text, then reading back the raw pixel data. Because font hinting, anti-aliasing, and GPU rendering differ slightly across hardware and driver combinations, the resulting pixels form a fingerprint that’s stable for a given machine and often unique enough to distinguish it from thousands of others.

WebGL fingerprinting does something similar but reads GPU-specific rendering parameters and a 3D-rendered test scene. It also exposes the UNMASKED_VENDOR_WEBGL and UNMASKED_RENDERER_WEBGL strings, which literally name your graphics card and driver unless something intercepts the call.

Anti-detect browsers handle this by injecting noise into the canvas output or spoofing the WebGL renderer strings per profile, so each profile draws a slightly different image and reports a different GPU. A checker site sees a passing “canvas: unique” or “canvas: masked” result. What it can’t tell you is whether the noise pattern itself has a signature. Randomizing a value in a way that’s consistent across every profile from the same tool is itself a fingerprint; a sophisticated detector doesn’t need to unmask the canvas, it just needs to recognize the shape of the masking.

Fonts, screen, and hardware: the quiet signals

Font enumeration checks which fonts are installed by measuring text width and height across a huge list of font names. A stock Windows install has a very different font list from a fresh Linux VPS, and font lists are one of the more common ways a “residential-looking” profile gets flagged as a virtual machine, because cloud images often ship a stripped-down font set.

Screen resolution, color depth, and hardware concurrency (reported CPU cores) round out the environment picture. These are cheap to spoof and most anti-detect tools do it by default, but they’re also cheap for a platform to cross-check against other signals. A profile claiming eight CPU cores and 16GB of RAM on a screen resolution that’s never shipped on real hardware is a mismatch, not a pass.

WebRTC and the IP problem

WebRTC is built for peer-to-peer connections, which means it can enumerate your local network interfaces and, in some configurations, leak your real public IP even when you’re routed through a proxy or VPN at the browser’s HTTP layer. This is one of the most common ways a “proxy is working” setup still exposes the real origin, because the leak happens at the WebRTC layer, not the HTTP layer the proxy controls.

A fingerprint checker site will usually show you the WebRTC-detected IPs directly. If that IP doesn’t match the IP your proxy is presenting, that’s a real, verifiable problem, not a cosmetic one. This is one of the few checks where the checker’s output and a platform’s actual detection genuinely overlap, because both are reading the exact same leak.

What a clean report actually tells you

A passing fingerprint checker result tells you three things, and only three things: the browser successfully spoofed or randomized the specific signals that checker measures, there’s no obvious mismatch between the spoofed values (like a phone user agent reporting a desktop screen size), and there’s no active WebRTC or DNS leak exposing your real network path at the time of the test.

It does not tell you whether the platform you’re actually using has its own fingerprinting stack that reads different signals, whether your account’s behavioral pattern matches thousands of other accounts created from the same tool in the same week, or whether the platform is correlating your device fingerprint against your payment method, phone number, or other accounts it already has on file. None of that shows up on a checker page, because none of it is a browser-readable signal.

Why the same browser scores differently on different sites

We’ve tested the same anti-detect browser profile across multiple checker sites and gotten different scores each time, because every checker site weighs signals differently and maintains its own comparison database. One site might flag a font mismatch that another ignores. One might test WebGL parameters that another skips entirely. There’s no single, standardized fingerprint score, in the same way there’s no single credit score model that every lender uses.

That’s worth knowing before you treat any single number as a target to hit. A profile tuned to score well on one checker isn’t necessarily tuned to survive scrutiny anywhere else, because “scrutiny” isn’t one test, it’s whatever detection stack the destination platform happens to run.

What we actually look for when testing a browser

When we put a tool like Multilogin, GoLogin, Kameleo, AdsPower, or Dolphin Anty through its paces, the checker site is step one, not the conclusion. We check whether the spoofed values are internally consistent with each other, whether the same profile produces the same fingerprint on repeat visits (some tools rotate more than they should, which is its own tell), and whether the WebRTC and IP layers actually agree with the proxy in front of them. Then we look at how the tool behaves over real sessions, not just a single page load, because a fingerprint checker is a ten-second test and a real account lives for months.

None of that adds up to a guarantee. No anti-detect browser makes an account undetectable, and no clean checker report means an account won’t get reviewed, limited, or banned. What a checker site gives you is a way to catch obvious, fixable problems, like a WebRTC leak or a mismatched hardware profile, before you find out about them the hard way.

If you want to see how specific anti-detect browsers actually perform under this kind of scrutiny, and what genuinely holds up versus what’s marketing, check out our reviews.

Get new guides and videos first — join the Telegram channel.

need infra for this today?