Multi-Signal Request Fingerprints: Combining TLS, HTTP and Network
How to design a composite request fingerprint from TLS, HTTP and network signals: picking fields, hashing them safely, and keeping implementations in sync.
read →Technical articles on TLS fingerprinting, detecting scrapers and spoofed crawlers, and blocking bots at the edge with Cloudflare Workers.
How TLS, HTTP and network signals identify the client behind a request, and why they beat IP addresses and user-agent strings for blocking bots.
How to design a composite request fingerprint from TLS, HTTP and network signals: picking fields, hashing them safely, and keeping implementations in sync.
read →How the TLS ClientHello reveals which software made a request, how JA3 and JA4 turn it into a fingerprint, and what Chrome's extension shuffling changed.
read →IP bans hit real users behind CGNAT and proxies while scrapers rotate addresses for pennies. Why IP-based bot blocking fails, and what to key on instead.
read →Spotting scrapers, scanners and spoofed crawlers: the signs to look for, verifying search engines, and controlling AI crawlers.
Which AI crawlers visit your site, what each one does with your content, and how to allow, block or limit them with robots.txt, verification and edge rules.
read →The symptoms of scraping and automated abuse in your analytics, logs and bills, how to confirm what's going on, and the practical steps to take next.
read →Many requests claiming to be Googlebot aren't. Verify crawlers with reverse and forward DNS or published IP ranges, and learn why user-agent checks aren't enough.
read →Protecting your site at the CDN edge: Cloudflare's bot products compared, designing checks that fail safely, and what blocking bots saves your origin.
Bots cost more than bandwidth: compute, database load, cache misses and skewed analytics. A simple model to estimate what bot traffic costs your origin.
read →What each Cloudflare bot product does, which plan includes it, and where the gaps are, so you can choose the right protection for your plan and your traffic.
read →When a security check errors, should the request go through or be blocked? A framework for choosing fail-open or fail-closed, with patterns that make either safe.
read →