Read directly from your browser's User-Agent and client hints. This is what every website you visit can see — it is reported, not guessed.
An IP address never carries an operating system. What it does carry is a network, a reverse DNS name and a connection class — enough for a reasoned estimate. Every result below shows its confidence and the exact signals behind it. Beta estimate, not a fact.
The Rainproxy Proxy Checker runs the same host OS and device estimation over up to 25 proxies at once. Switch on “Detect host OS & device” before you run the check, and the result is added to every row and to the CSV export.
There are two completely different questions hiding behind “OS detection”, and mixing them up is where most confusion starts. The first is what operating system is this visitor on? — answered by the browser itself. The second is what machine sits behind this IP address? — which can only ever be estimated.
Every HTTP request your browser sends includes a User-Agent header, a short string naming the browser, its version, the rendering engine and the operating system. Chromium browsers additionally send User-Agent Client Hints, a structured version of the same data that can be queried with higher entropy: platform, platform version, CPU architecture, bitness and even the device model on Android. That is why the card at the top of this page can name your OS and version outright rather than guessing. Firefox and Safari still rely on the classic User-Agent string, which is why some fields read “Not reported” there.
Beyond the headers, a site can narrow things further with JavaScript: the number of logical CPU threads, screen size and pixel ratio, touch point count, installed font metrics, WebGL renderer strings and how the platform rasterises canvas output. Combined, these form a device fingerprint that survives a User-Agent change — which is exactly why simply spoofing a User-Agent rarely fools a serious anti-bot system.
An IP address is an address on a network, not a machine identifier. Nothing in the packet says “Windows 11”. What you can read is the surrounding context. Reverse DNS often encodes exactly what the device is — names containing cpe, dyn, dsl, cable or ppp almost always sit on consumer lines behind a router, while names containing lte, mobile or a carrier brand indicate a cellular connection. The ASN and ISP tell you whether the range belongs to a hosting company, a broadband provider or a mobile operator. Public IP intelligence adds mobile, hosting and proxy flags.
From there the estimate is statistical rather than certain. Mobile carrier exits are overwhelmingly Android handsets or LTE modems. Datacenter ranges are overwhelmingly Linux servers. Consumer lines that answer on a proxy port and resolve to CPE-style names are usually embedded router firmware such as OpenWrt, RouterOS or a vendor build. When a proxy echoes back a Server or Viaheader naming Squid, nginx, 3proxy or Microsoft-IIS, that is a much stronger signal, because proxy software ships per platform.
This tool only reports high confidence when at least two strong, independent signals agree. One strong signal gives medium confidence, weak hints alone give low confidence, and when nothing useful is available the answer stays “Not determined”. We would rather show you an honest blank than a fabricated operating system.
Routing through a residential proxy replaces the IP a site sees, so the location, ISP and ASN all change with it — and any OS estimate made from the IP now describes the proxy's exit host, not you. Your browser keeps sending the same User-Agent, the same client hints and the same canvas fingerprint. That mismatch — a German residential IP paired with a headless Linux fingerprint, for instance — is one of the cheapest detection signals there is. If you are automating at scale, match the fingerprint to the exit: mobile IPs should carry mobile fingerprints, US residential IPs should carry a plausible US desktop profile.
Rainproxy residential and mobile IPs come from real consumer lines and carriers, so the host profile behind your traffic matches the story your browser tells. 250 MB free, activated by our team in live chat, with city/state targeting, IP quality filter and speed filter included.
One is read straight from the browser. The other is estimated from the network an IP address lives on.
User-Agent plus client hints give the operating system, version, architecture and device class, exactly as a website would see them.
We resolve reverse DNS, ISP, ASN and range type for that address — no connection to the host is made.
Naming patterns, network class and any echoed server headers are combined into an OS and device guess with a confidence level.
Lookups run and are forgotten. No account, no logging of the IPs you check.
Both address families are accepted, including compressed IPv6 notation.
You always see why we reached a conclusion, so you can judge it yourself instead of trusting a label.
This free Rainproxy tool answers two questions: what operating system, device and browser you are using right now, and what operating system is likely running behind a given IP address. The first is read from your own request, the second is an estimate based on how the remote host responds.
Your browser reports its platform through the User-Agent string and, in Chromium browsers, through client hints that give a more accurate OS version. That is enough to name the operating system, the major version, the device class and the browser reliably, without any permissions or fingerprinting.
A remote host cannot be asked what it runs, but its network behaviour hints at it. TTL values, TCP window sizes and the order and content of response headers differ between Linux, Windows and BSD-derived systems. The tool combines those signals into a best guess with a confidence level. It is an estimate: firewalls, load balancers and CDNs rewrite exactly the fields it relies on.
Support teams use it to confirm what a user is actually running before debugging. Security and infrastructure teams use host estimation for quick inventory checks. If you are scraping, it is a reminder that the same signals work in reverse: a request claiming to be an iPhone from a Linux datacenter host, over a datacenter IP, is easy to spot. Matching device, headers and IP type is what makes traffic look ordinary.