zoleb.com — what your browser is telling the world



Known identifying headers

Curated list of HTTP request headers most commonly used for identification: IP, user-agent, Client Hints, and geolocation from Cloudflare's edge. Your browser sent these automatically when it requested this page; this server did not request any extraneous data from you. Source: nginx passing through headers received from Cloudflare, read by this Python app.

FieldSourceValue
IP addressCF-Connecting-IPset by Cloudflare edge216.73.217.58
IPv6CF-Connecting-IPv6set by Cloudflare edgeunavailable
CountryCF-IPCountryCloudflare GeoIP — approximateUS
CityCF-IPCityCloudflare GeoIP — approximateunavailable
Cloudflare Ray IDCF-Rayrequest ID + datacenter codea0714c102b5f36cd-CMH
CF-VisitorCF-VisitorCloudflare — original scheme{"scheme":"https"}
User-AgentUser-AgentHTTP header — easily spoofedMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])
LanguagesAccept-LanguageHTTP header — locale preferencesunavailable
AcceptAcceptHTTP header*/*
Accept-EncodingAccept-EncodingHTTP headergzip, br
RefererRefererHTTP header — previous page, may be suppressedunavailable
Do Not TrackDNTHTTP header — honored by almost no oneunavailable
UA brandSec-CH-UAClient Hints — low entropyunavailable
UA mobileSec-CH-UA-MobileClient Hints — low entropyunavailable
UA platformSec-CH-UA-PlatformClient Hints — low entropyunavailable
UA platform verSec-CH-UA-Platform-VersionClient Hints — high entropy, site must opt-inunavailable
UA architectureSec-CH-UA-ArchClient Hints — high entropy, site must opt-inunavailable
UA modelSec-CH-UA-ModelClient Hints — high entropy, site must opt-inunavailable
Fetch siteSec-Fetch-SiteHTTP header — how you arrivedunavailable
Fetch modeSec-Fetch-ModeHTTP headerunavailable
Fetch destSec-Fetch-DestHTTP headerunavailable
Upgrade requestsUpgrade-Insecure-RequestsHTTP headerunavailable

Other request headers

Every remaining header your browser or Cloudflare attached to this request. These aren't primarily used for fingerprinting, but they were sent all the same. This is the complete set the origin server received.

HeaderSourceValue
ConnectionHTTP headerclose
HostHTTP headerzoleb.com
X-Forwarded-ForHTTP header216.73.217.58
X-Forwarded-ProtoHTTP headerhttps
X-Real-IPHTTP header216.73.217.58
cdn-loopHTTP headercloudflare; loops=1

JavaScript derived identifiers

Collected by JavaScript running in your browser, right now, by calling the APIs listed in the Source column (navigator, screen, Intl, WebGL, OfflineAudioContext, and a canvas render), then POSTed back to /log on this server so you can see what was gathered. Many values are estimates, buckets, or clamped by the browser to reduce fingerprinting; the Source column notes each API and any known caps.

FieldSourceValue
collecting…