Read directly from your browser's User-Agent and client hints. This is what every website you visit can see — it is reported, not guessed.
An IP address never carries an operating system. What it does carry is a network, a reverse DNS name and a connection class — enough for a reasoned estimate. Every result below shows its confidence and the exact signals behind it. Beta estimate, not a fact.
The Rainproxy Proxy Checker runs the same host OS and device estimation over up to 25 proxies at once. Switch on “Detect host OS & device” before you run the check, and the result is added to every row and to the CSV export.
There are two completely different questions hiding behind “OS detection”, and mixing them up is where most confusion starts. The first is what operating system is this visitor on? — answered by the browser itself. The second is what machine sits behind this IP address? — which can only ever be estimated.
Every HTTP request your browser sends includes a User-Agent header, a short string naming the browser, its version, the rendering engine and the operating system. Chromium browsers additionally send User-Agent Client Hints, a structured version of the same data that can be queried with higher entropy: platform, platform version, CPU architecture, bitness and even the device model on Android. That is why the card at the top of this page can name your OS and version outright rather than guessing. Firefox and Safari still rely on the classic User-Agent string, which is why some fields read “Not reported” there.
Beyond the headers, a site can narrow things further with JavaScript: the number of logical CPU threads, screen size and pixel ratio, touch point count, installed font metrics, WebGL renderer strings and how the platform rasterises canvas output. Combined, these form a device fingerprint that survives a User-Agent change — which is exactly why simply spoofing a User-Agent rarely fools a serious anti-bot system.
An IP address is an address on a network, not a machine identifier. Nothing in the packet says “Windows 11”. What you can read is the surrounding context. Reverse DNS often encodes exactly what the device is — names containing cpe, dyn, dsl, cable or ppp almost always sit on consumer lines behind a router, while names containing lte, mobile or a carrier brand indicate a cellular connection. The ASN and ISP tell you whether the range belongs to a hosting company, a broadband provider or a mobile operator. Public IP intelligence adds mobile, hosting and proxy flags.
From there the estimate is statistical rather than certain. Mobile carrier exits are overwhelmingly Android handsets or LTE modems. Datacenter ranges are overwhelmingly Linux servers. Consumer lines that answer on a proxy port and resolve to CPE-style names are usually embedded router firmware such as OpenWrt, RouterOS or a vendor build. When a proxy echoes back a Server or Viaheader naming Squid, nginx, 3proxy or Microsoft-IIS, that is a much stronger signal, because proxy software ships per platform.
This tool only reports high confidence when at least two strong, independent signals agree. One strong signal gives medium confidence, weak hints alone give low confidence, and when nothing useful is available the answer stays “Not determined”. We would rather show you an honest blank than a fabricated operating system.
Routing through a residential proxy replaces the IP a site sees, so the location, ISP and ASN all change with it — and any OS estimate made from the IP now describes the proxy's exit host, not you. Your browser keeps sending the same User-Agent, the same client hints and the same canvas fingerprint. That mismatch — a German residential IP paired with a headless Linux fingerprint, for instance — is one of the cheapest detection signals there is. If you are automating at scale, match the fingerprint to the exit: mobile IPs should carry mobile fingerprints, US residential IPs should carry a plausible US desktop profile.
Yes. Every request your browser makes carries a User-Agent string and, in Chromium browsers, User-Agent Client Hints. Those name the operating system, its major version, the CPU architecture and whether the device is mobile. Sites can also infer the OS from installed fonts, rendering differences and touch support.
No, not with certainty. An IP address identifies a network, not a machine. What you can do is estimate: reverse DNS naming, the ISP or hosting provider behind the ASN, and whether the range is a mobile carrier, a broadband line or a datacenter all point towards a likely class of device and OS. This tool shows that estimate with a confidence level and lists every signal it used.
Detection from your own browser is exact, because your browser reports it. Detection from an IP address is a guess. We only report high confidence when several independent signals agree, and we show 'Not determined' instead of inventing an answer.
A proxy hides your IP address and therefore your location and ISP, but it does not change the User-Agent your browser sends. To change what the OS looks like you also need to change the browser fingerprint, which anti-detect browsers do.
Use the Rainproxy Proxy Checker and switch on 'Detect host OS & device'. It runs the same estimation over up to 25 proxies at once and exports the result to CSV.
Rainproxy residential and mobile IPs come from real consumer lines and carriers, so the host profile behind your traffic matches the story your browser tells. 250 MB free, activated by our team in live chat, with city/state targeting, IP quality filter and speed filter included.
One is read straight from the browser. The other is estimated from the network an IP address lives on.
User-Agent plus client hints give the operating system, version, architecture and device class, exactly as a website would see them.
We resolve reverse DNS, ISP, ASN and range type for that address — no connection to the host is made.
Naming patterns, network class and any echoed server headers are combined into an OS and device guess with a confidence level.
Lookups run and are forgotten. No account, no logging of the IPs you check.
Both address families are accepted, including compressed IPv6 notation.
You always see why we reached a conclusion, so you can judge it yourself instead of trusting a label.