TLS Fingerprinting Through a Proxy: JA3 & JA4
published 2026-09-10
by Paul Wang
26 views
A proxy can give your requests a different IP address while leaving your client’s TLS fingerprint intact. Websites can recognize patterns in the handshake that establishes the encrypted connection, before they receive an HTTP request.
An opaque SOCKS5 or HTTP CONNECT tunnel forwards that handshake. TLS interception creates a new outbound handshake, which can reveal the proxy’s transport stack instead.
We tested 17 client configurations across seven connection paths to see which JA3, JA4, and HTTP/2 signals changed. This article explains the results and shows how to check your own client.





