Skip to content
Fingerprinting

Timezone & Locale Fingerprinting

Timezone and locale fingerprinting uses a device's configured timezone, language preferences, date and number formatting, and related regional settings as identifying and corroborating signals. These values reflect where and how a user has set up their device, and fraud-detection systems commonly compare them against network geolocation.

How it works

How Timezone & Locale Fingerprinting works

Browsers expose the system timezone, the ordered list of preferred languages, and the internationalization settings that govern how dates, numbers, and currencies are formatted. Scripts read these directly, and the resolved timezone can be obtained precisely through the Internationalization API.

Individually these values are shared by many users, but the combination of an unusual timezone with a particular language ordering and formatting locale adds entropy. More importantly, they provide context that can be cross-checked against other signals such as the IP-based location.

Because a user rarely changes their timezone or language settings, these signals are quite stable. Their main analytical value lies in consistency checks: a browser reporting one region while its network location indicates another is a classic anomaly.

Why it matters

Why Timezone & Locale Fingerprinting matters for fraud prevention

Timezone and locale signals are highly effective at exposing evasion, because fraudsters routing through proxies often forget to align their device locale with the IP location they are borrowing. A device claiming one timezone while connecting from a mismatched geography is a strong fraud indicator. These signals thus power geolocation consistency checks central to many risk models.

With TRACIO

How TRACIO handles it

TRACIO reads timezone and locale as device signals, and their job is identification rather than geography. The timezone is one axis of the device profile, normalized so that two browser engines naming the same zone differently still resolve to one device instead of two. It is not cross-checked against the IP-derived location: the location contradiction that feeds its risk score comes from the network side, where an address leaked through WebRTC resolves to a country other than the one the connecting IP belongs to. On their own, timezone and locale add only modest entropy and are never treated as unique identifiers.

FAQ

Frequently asked questions

Identify every device with confidence

Start with a free plan of 2,500 API calls per month. No credit card required.