User Agent
An HTTP header string that identifies the browser, version, and operating system making a request.
A user agent is a string your client sends in the User-Agent HTTP header to identify itself - its browser, version, rendering engine, and operating system. A real Chrome browser on Windows sends something like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ... Chrome/120.0". Servers read it to decide what content and formatting to return.
For scraping, the user agent is a common detection point. Default HTTP libraries send obvious bot user agents (e.g. "python-requests/2.31"), which anti-bot systems flag instantly. Sending a realistic browser user agent is a baseline requirement to avoid being blocked on sight.
Beyond just setting one realistic value, rotating user agents across requests helps traffic look like many different users. But the user agent must stay consistent with the rest of your request - claiming to be Chrome while sending headers or a TLS fingerprint that Chrome would never send is a red flag that sophisticated systems detect.
User agent is one signal among many. Pair a realistic, rotated user agent with matching Accept and Accept-Language headers, a coherent TLS fingerprint, and rotating IPs. Faking the user agent alone, while everything else screams "bot," will not get you far against modern anti-bot defenses.
A string that has to agree with everything else
The User-Agent header is a self-reported description of your browser and operating system. It is trivially editable, which is why no serious anti-bot system trusts it on its own. What those systems do instead is check whether it agrees with everything they can measure independently.
The list of independent measurements is long. The TLS handshake produces a fingerprint that differs between Chrome, Firefox and a Python library. The order of your HTTP headers differs between real browsers and most automation tools. JavaScript exposes the screen size, the platform, the font list, the number of CPU cores and the graphics renderer. The TCP stack itself has an operating-system flavour.
A request claiming to be Chrome on Windows while presenting a Python TLS fingerprint, sending headers in the wrong order and reporting a Linux platform in JavaScript is not a browser. Sites do not need to guess. The contradiction is arithmetic.
This is why changing the User-Agent alone almost never helps, and occasionally hurts: a mismatched string turns a consistent automated client into an inconsistent one, which is the pattern detection systems are actually built to find.
Where the proxy fits into fingerprint consistency
The address is one signal among many, and it has to agree with the others. On mobile modems you can also align the network stack:
Set the modem fingerprint to match the profile
# Supported values on our mobile modems:
android:1 android:3
ios:1 ios:2
macosx:3 macosx:4
windows:1
# An iPhone profile behind a modem announcing Windows
# contradicts itself before any script runs.- Match the proxy country to the profile locale and timezone. A US address with a Warsaw timezone is a contradiction visible in one line of JavaScript.
- On mobile, set the OS fingerprint when you create the profile and leave it. Changing it later looks like the device was replaced overnight.
- Let your antidetect browser generate the User-Agent rather than typing one. Hand-written strings drift out of date and stop matching the browser version behind them.
- A proxy fixes the address. Fingerprint consistency is a separate job, and the two have to be solved together to be worth anything.
What the User-Agent will and will not do
Changing it does not make you a different browser
Everything measurable stays the same, and now it disagrees with your claim.
Mobile User-Agent without a mobile address
Claiming an iPhone from a datacenter range is a contradiction that costs nothing to detect.
A blocked request is rarely about the string
Most blocks are decided on address reputation and TLS fingerprint. The header is the last thing checked, not the first.
Rotating User-Agents per request
Real browsers keep theirs. A session where the browser changes identity every request is more suspicious than one that repeats.
See this in practice
Ready to use user agent?
SotaProxy gives you access to rotating residential, mobile, datacenter, and ISP proxies. No minimum commitment.
Get started