tls-reputation.comTLS fingerprint reputation

known client

Apple Safari / WebKit

Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated

Unclassified

Too few observations to classify this stack — a handful of connections can't tell a permuting client from coincidence.

TLS 1.3ALPN h2 · http/1.12026-07-23 → 2026-07-23
JA4
JA4_r
JA3
JA3_raw
This JA3 resolves unambiguously to the JA4 above.

explore in graph →

Read

catalog identity
Matches Apple Safari / WebKit in the ground-truth catalogue.
self-randomisation
unclassified — only 1 observation(s) — too few to tell a permuting client from a coincidence.
real-browser tell
Advertises X25519MLKEM768 (0x11ec), a post-quantum key share only current real browsers send.
reach
0.000effectively one destination.

Spread measures reach, not intent: it can’t tell one scraper visiting 500 domains from 500 people visiting one each. Stability is a claim about software — whether the stack is deterministic — nothing about who runs it.

Footprint

1
observations
1
domains reached
2026-07-23
first seen
2026-07-23
last seen

ClientHello anatomy

The underscore groups of JA4_r are the raw cipher suites · extensions · signature algorithms behind the hash.

TLS version
TLS 1.3
ALPN (wire order)
h2, http/1.1
EC point formats
0x0000
Post-quantum key share
present (X25519MLKEM768)

The post-quantum key share is a structural fact about the hello, not a verdict — GREASE values are flagged the same neutral way.

cipher suites(20)
  1. 00x1302TLS_AES_256_GCM_SHA384
  2. 10x1303TLS_CHACHA20_POLY1305_SHA256
  3. 20x1301TLS_AES_128_GCM_SHA256
  4. 30xc02cTLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  5. 40xc02bTLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  6. 50xcca9TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
  7. 60xc030TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  8. 70xc02fTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  9. 80xcca8TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
  10. 90xc00aTLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
  11. 100xc009TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
  12. 110xc014TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  13. 120xc013TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  14. 130x009dTLS_RSA_WITH_AES_256_GCM_SHA384
  15. 140x009cTLS_RSA_WITH_AES_128_GCM_SHA256
  16. 150x0035TLS_RSA_WITH_AES_256_CBC_SHA
  17. 160x002fTLS_RSA_WITH_AES_128_CBC_SHA
  18. 170xc008unknown (0xc008)
  19. 180xc012unknown (0xc012)
  20. 190x000aunknown (0x000a)
extensions(15)sorted
  1. 00x0000server_name (SNI)
  2. 10x0005status_request (OCSP)
  3. 20x000asupported_groups
  4. 30x000bec_point_formats
  5. 40x000dsignature_algorithms
  6. 50x0010application_layer_protocol_negotiation (ALPN)
  7. 60x0012signed_certificate_timestamp
  8. 70x0017extended_master_secret
  9. 80x001bcompress_certificate
  10. 90x0023session_ticket
  11. 100x0029unknown (0x0029)
  12. 110x002bsupported_versions
  13. 120x002dpsk_key_exchange_modes
  14. 130x0033key_share
  15. 140xff01renegotiation_info

Stored sorted — under one JA4 the wire order varies by construction, so no single order is “the” order.

curves / groups(5)
  1. 00x11ecX25519MLKEM768 PQ
  2. 10x001dx25519
  3. 20x0017secp256r1 (P-256)
  4. 30x0018secp384r1 (P-384)
  5. 40x0019secp521r1 (P-521)
signature algorithms(10)
  1. 00x0403ecdsa_secp256r1_sha256
  2. 10x0804rsa_pss_rsae_sha256
  3. 20x0401rsa_pkcs1_sha256
  4. 30x0503ecdsa_secp384r1_sha384
  5. 40x0805rsa_pss_rsae_sha384
  6. 50x0805rsa_pss_rsae_sha384
  7. 60x0501rsa_pkcs1_sha384
  8. 70x0806rsa_pss_rsae_sha512
  9. 80x0601rsa_pkcs1_sha512
  10. 90x0201rsa_pkcs1_sha1

Reach — domains contacted

Top 1 of 1. Share is the fraction of this fingerprint’s observations reaching each name.