What your browser reveals before the first click
Even a brief visit leaves traces. What do your IP address, cookies and browser fingerprint reveal, and which can identify you?

Original AI-generated illustration · SecuFocus
At a glance
Key points
A page receives information it needs to work and may collect more to recognise you. IP addresses, cookies, browser fingerprints and signed-in accounts play distinct roles. Reducing one clue does not remove the others.
Opening the page starts the exchange
You open an article. You have not filled in a form, accepted notifications or clicked a button. Your browser has nevertheless already communicated to request the page. The server needs a route for its reply and receives information about the request.
Separate that necessary exchange from the uses a website may make of it. Adapting a page to a screen, keeping a basket and connecting your reading to other visits are different operations. Some may use the same clues, with very different consequences.
Your browser already sends information to load the page. To understand tracking, look at who receives it, how long they keep it and what other data it can be linked to.
Four clues, four mechanisms
A cookie stores information the browser can send back to the relevant site. It can support a session or tracking. Fingerprinting works differently: it combines accessible characteristics such as language, time zone and certain capabilities of the environment.
An IP address places a connection on the network; it is not a reliable identity card for a person. Several people may share an exit address, and an address may change. A signed-in account, on the other hand, directly associates actions with that account even after the network address changes.
Scroll the table sideways to read every column.
| Clue | Possible use | What it does not prove alone |
|---|---|---|
| IP address | Recognise a connection or approximate area | Who is holding the device |
| Cookie | Retrieve a session or stored identifier | The visitor’s legal identity |
| Fingerprint | Associate similar configurations | Global uniqueness or a certain match |
| Signed-in account | Associate an action with an authenticated profile | That only its owner uses the session |
Fingerprinting: recognising a combination
Knowing that your browser uses English tells relatively little. Add a time zone, dimensions and certain capabilities and the combination becomes more descriptive. Its strength still depends on the observed population, changes over time and protections that alter the answers.
An impressive number on a test page deserves questions. Which visitors form the comparison set? When was it collected? Does the measurement survive an update? “Rare in this sample” and “identifiable everywhere” are not equivalent findings.
The properties described here explain how a fingerprint can be formed. We have not measured their ability to identify a visitor.
Third parties on the page
A page may load resources from several services: images, fonts, video players, advertising or analytics. A request to another domain adds a technical recipient. Its presence alone does not establish advertising use; it tells you where to investigate next.
Your browser’s developer tools can show a page’s requests. Open the Network panel, reload an ordinary page and inspect the domain names. Start by counting the parties involved and identifying their apparent roles rather than searching for one mysterious line.
Do not publish a raw network export when asking for help. Depending on the capture, it may contain session tokens, personal parameters or request content. A cleaned list of domains often answers the first question.
Inspect your browser in the Lab
The SecuFocus Lab displays properties including language, time zone and window dimensions. Resize the window and run the observation again: some values change while others stay the same.
The experiment does not calculate uniqueness or examine every tracking method. It does not establish what other websites do either. Information absent from our demonstration is not guaranteed to be unavailable elsewhere.
When comparing browsers, record their versions and any altered settings. You can then describe a precise observation: “this property changes with window size”. Avoid turning that local result into an overall privacy ranking.
Reduce the traces you leave
Start with the behaviour you want to limit. If a site recognises you because you are signed in, changing VPN servers does not close the session. If a location permission bothers you, clearing cookies is not the most direct way to revoke it.
- To reduce persistent access, review site permissions and remove those without a current purpose.
- To limit some cross-site tracking, use browser protections and review the exceptions you create.
- To prevent mistakes between accounts, separate sign-in contexts and check the active profile before posting.
- To reduce exposure of your home IP address, examine the role of a VPN while keeping other clues in the picture.
- To limit traces on a shared device, understand Private Browsing’s limitations and close the relevant sessions.
Signing in changes what a site knows
You do not need to turn every website into an investigation. Save that effort for activities that matter: an important sign-in, a new extension or a service receiving your documents.
Identify what links your visits: an account, a cookie, an IP address or your browser fingerprint. Changing your IP address does not hide your identity from a site you are signed in to. Deleting cookies may end the local session, but does not delete the account or data the service has already stored.
What can this page see about your browser?
Open the Lab experiment
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- MDN: how HTTP exchanges work ↗developer.mozilla.org ·
- MDN: browser fingerprinting ↗developer.mozilla.org ·
- Firefox: developer tools Network Monitor ↗firefox-source-docs.mozilla.org ·Used in:Third parties on the page
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.