How to understand TCP/IP OS mismatches
If your Multilogin profile says Windows but a TCP/IP checker says Linux, that doesn’t automatically mean your profile is wrong. TCP/IP fingerprinting looks at the network connection, which can be affected by a proxy, VM, or other part of the network path.
➡️ If the OS doesn’t match: check your proxy or VM setup first – don’t change Canvas, WebGL, Navigator, or other browser fingerprint settings.
📱 Need a mobile environment rather than a browser setup? Android cloud phones combine real cloud-hosted Android devices with mobile-grade proxies, so you can run native Android apps from the same Multilogin dashboard. Explore cloud phones.
What is TCP/IP fingerprinting?
When you connect to a website, your device sends network packets.
Different operating systems and network stacks handle those packets in slightly different ways. A server can look at details in the connection and estimate which OS or network stack is behind it.
That’s called passive OS fingerprinting. It looks at traffic you’re already sending – it doesn’t need to run a special fingerprinting script inside your browser.
Think of it like this:
- Browser fingerprint – describes the browser environment
- TCP/IP fingerprint – describes the network connection
So the two results don’t always have to match.
How to check your TCP/IP fingerprint
Open BrowserLeaks IP and find “TCP/IP Fingerprint".
You may see something like:
Multilogin profile: Windows
TCP/IP fingerprint: Linux
Before changing anything, check whether you’re using a proxy or virtual machine. Either can affect what the checker sees.
Why can the OS result be different?
The most common reason is that something sits between your browser and the website.
If you’re using a proxy
Your browser connects through the proxy before reaching the website. In common proxy setups, the outgoing connection is created from the proxy side.
So you could have:
💻 Your computer – Windows
🌐 Your Multilogin profile – Windows
🔀 Your proxy server – Linux
🔎 TCP/IP checker – Linux
Nothing has changed inside your browser profile. The checker is just looking at a different part of the connection.
If you’re using a virtual machine
A VM can affect the result too, and it depends on how its networking is set up.
For example, NAT and bridged networking handle traffic differently. That means a TCP/IP checker may pick up characteristics from the VM, host, or another part of the network path.
So if you run Multilogin in a VM, don’t expect the TCP/IP result to always match the OS selected in the profile.
Can Multilogin mask the TCP/IP fingerprint?
Not through a browser fingerprint setting.
TCP/IP fingerprinting happens outside the browser. Settings such as Canvas, WebGL, fonts, and Navigator don’t control the network connection underneath them.
So if BrowserLeaks shows a different OS, changing those settings won’t fix it.
If you need to change the connection-level result, that has to happen in the network setup – for example, through the proxy, VM, VPN, or networking mode you’re using.
Should I worry if the OS doesn’t match?
Usually, there’s no reason to panic. 🙂
A mismatch only tells you this:
The OS selected in your browser profile and the OS estimated from the network connection are different.
It doesn’t prove that your profile is broken, and it can’t tell you by itself how a specific website will react.
What should I do if BrowserLeaks shows the “wrong” OS?
Start with your connection:
- Using a proxy? The result may reflect the proxy’s side of the connection
- Using a VM? Check its network mode – NAT and bridged networking can behave differently
- Using neither? The result is more likely to come from the device making the direct connection
Simple rule: don’t change Canvas, WebGL, Navigator, or other browser fingerprint settings to fix a TCP/IP OS result. They control a different layer.
If you’re still not sure whether the result makes sense, contact Multilogin support and send:
- A screenshot of the BrowserLeaks result
- Your browser profile ID
- The OS of the computer you’re using
- Whether you’re using a proxy or VM