What it is
Do Not Track is a one-bit request not to be tracked, sent as a header and readable from navigator.doNotTrack. Global Privacy Control is its newer, legally backed cousin (Sec-GPC). Almost no site honours DNT, but every site can read it.
How websites read it
navigator.doNotTrack // "1" · "0" · null
navigator.globalPrivacyControl // true when GPC is on
Sec-GPC: 1 // sent as a header tooBoth values are available to scripts and travel as headers. They are stable for as long as the setting is.
Why it identifies you
Because only a few percent of users enable either flag, turning one on makes you rarer — a small but real contribution to the fingerprint, and one that persists across every site you visit.
How risk-control systems use it
Not a consistency check so much as a rarity check. A DNT or GPC flag that differs between the header and the JavaScript property, or that is set on a browser whose default cannot send it, is the only real contradiction.
Common mistakes
Enabling DNT on every profile "for privacy" and making all of them stand out together; a header and a property that disagree.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
CustomConfigurable per profile; default matches the browser default (off).
Check yours
Jump to this signal in your scan results.