Skip to main content

Your fonts reveal the software behind your browser.

A website does not need a list of files from your computer. It can ask the browser to render the same characters again and again, then use changes in width and shape to infer which fonts are available. Those measurements become more useful when assembled with the rest of a browser fingerprint.

Permission
Not requested
Stored ID
Not required
Primary clue
Text metrics
Stronger with
Other signals
Same requestWm1lI0 @ 72px
system sansWm1lI0318.42 px
system serifWm1lI0302.17 px
monospaceWm1lI0346.80 px
The text says the same thing. Its measurements describe the environment that rendered it.

See which candidate fonts change the measurement.

This local demonstration compares a test string against three generic fallback families. A changed width suggests that a candidate font rendered. Results stay in this page.

Local measurement

Probe this browser

The test uses a short candidate list for illustration, not exhaustive enumeration.

Waiting to measure—candidate fonts detected
Illustrative local digestnot generatedA production system would combine a much larger set of values.
  • Run the test to compare candidate fonts with local fallbacks.

Computation happens in your browser. The page does not transmit or retain the result.

The browser can reveal a font without naming it directly.

  1. 01

    Establish a fallback

    The page measures a test string in a generic family such as monospace, serif, or sans-serif.

  2. 02

    Request a candidate font

    The same string is measured again with a named local font placed before the fallback.

  3. 03

    Compare the metrics

    If the width or glyph bounds change, the named font likely rendered. Repeating the test produces a font inventory.

  4. 04

    Combine the evidence

    Presence results and exact measurements can be joined with locale, platform, canvas, and other browser signals.

One API call can return precise text dimensions.

Canvas measureText() returns a TextMetrics object. A script can repeat the measurement across candidate names, sizes, weights, scripts, and fallback families.

const baseline = width('monospace');
const candidate = width('"Font Name", monospace');

if (candidate !== baseline) {
  profile.fonts.push('Font Name');
}

A font list can become a map of the machine.

A typeface is not proof that a particular application, language, or operating system is present. It is a clue. Multiple related fonts make the inference stronger.

Observed families
Operating systemSegoe UI · San Francisco · Ubuntu · Liberation Sans

Default fonts can narrow the likely platform family.

ApplicationsCalibri · Cambria · Adobe families · developer fonts

Installed software may add recognizable typefaces.

Language supportNoto CJK · Arabic families · Indic scripts · emoji fonts

Language packs and fallback coverage can expose regional context.

Personal choicesdesign fonts · custom monospace · downloaded families · legacy collections

A rare combination can separate one machine from otherwise similar devices.

Good analysis separates observation from inference: “Calibri measured differently” is an observation; “Microsoft Office is installed” is a plausible but unproven explanation.

Installed fonts and rendered glyphs answer different questions.

01

Font inventory

Which named families appear to be available?

  • Operating-system defaults
  • Language packs
  • Fonts added by applications
  • User-installed typefaces
02

Rendering behavior

How does this environment shape and measure text?

  • Glyph width and bounds
  • Font version differences
  • Hinting and rasterization
  • Canvas pixel output

Network resets do not rewrite the local font environment.

ActionLikely effectWhy
Clear cookies or site dataFont set usually stays the same

Stored identifiers are removed; local software is not.

Open a private windowDepends on browser protections

The session is separate, but font exposure may remain similar or be restricted.

Change VPN or networkFont set usually stays the same

The route and IP change; local typography does not.

Install or remove fontsInventory can change

The browser may expose a different set of measurable families.

Change OS, browser, or text stackMetrics can change

Fallbacks, rasterization, hinting, and available families may differ.

Enable browser fingerprinting defensesExposure may be reduced

A browser can limit local fonts or standardize what pages can use.

The goal is to make your font profile less unusual.

Removing one rare font may change a fingerprint, but manual customization can create a new rare configuration. Stronger defenses reduce the number of answers a browser can give and place users into larger groups.

Firefox can restrict locally installed fonts when fingerprinting protection is active. Tor Browser limits font enumeration and character fallback as part of a broader standardization strategy.

  1. 01

    Limit local font exposure

    Allow pages to use a smaller, common set instead of every font installed on the machine.

  2. 02

    Standardize the visible set

    A shared bundle helps many users return the same answers instead of inventing a unique answer for each person.

  3. 03

    Protect related surfaces

    Font inventory is only one path. Canvas text, glyph metrics, locale, and platform data can reinforce the same inference.