Free fingerprinting tool·CDN-aware detection

Web server detector: see what any site runs

Run a free web server detector on any website: identify Apache, Nginx and more, detect the underlying technology, and get confidence-rated results — even behind CDNs. No signup needed.

Passive, header-only
Confidence rated
Enter a domain to guess its backend OS.
Try github.com, wikipedia.org, or your own site.
What you get

Know the stack, behind any site

Server and technology detection with honest confidence ratings.

Web server detection

Identify whether a site runs Apache, Nginx, LiteSpeed or another server from its response headers and behaviour.

Confidence ratings

Every guess is rated High, Medium or Low, so you know how much to trust the result before acting on it.

CDN-aware analysis

Detects when Cloudflare or other CDNs mask the origin server, and reports what's visible instead of guessing wrong.

Technology signals

Beyond the server header, the tool reads technology fingerprints — frameworks, platforms and headers — to build the full picture.

Stop second-guessing.

Find your domain in the next 30 seconds.

Free forever. No login required. 1,100+ TLDs in one query — plus AI suggestions and the premium marketplace.

1,147
TLDs
200ms
Avg lookup
100
Suggestions/query
FAQ

Web server detector FAQs

Enter the URL and the detector analyses response headers, header order and behavioural signals to identify the server — Apache, Nginx, LiteSpeed and others. Results include a confidence rating, and CDN masking is flagged rather than guessed through.
Hiding or changing the Server header is security through obscurity — it stops casual fingerprinting but won't slow a determined attacker, who has other signals to work with. It's harmless to do, but real security comes from patching, minimal headers and hardened configuration, not secrecy alone.
Apache and Nginx send distinct header combinations, error pages and connection behaviours. The detector compares these fingerprints against known patterns for each. Many sites run both — for example Nginx as a reverse proxy in front of Apache — and the report reflects that.
CDNs like Cloudflare terminate the connection themselves, so their headers replace the origin server's. The tool detects this masking and says so honestly with a confidence rating, rather than inventing an origin it can't actually see.
Low confidence means the signals were weak, mixed or masked — the guess is a best effort, not a fact. High means multiple independent signals agree. Treat Low results as a starting point and verify with other reconnaissance before drawing conclusions.
Yes — server banners and behaviour often leak the OS family, such as Linux versus Windows. OS guesses are confidence-rated High, Medium or Low, and CDN-masked sites report what the edge network reveals rather than the hidden origin.