Why every User-Agent starts with "Mozilla/5.0"#
This is one of the most-asked "why" questions about the web platform: every major browser, including Chrome, Safari and Edge, includes Mozilla/5.0 at the start of its User-Agent string, even though none of them are Mozilla software. It is a historical artifact — in the 1990s, sites checked for the Mozilla token to decide whether to serve advanced HTML features, and rather than break compatibility, every subsequent browser kept including it. Parsing a UA string correctly means looking past this token entirely and searching for the more specific ones further in.
Why order matters more than pattern matching#
A Chrome-based Edge UA string contains both Chrome/120.0.0.0 and Edg/120.0.0.0 — checking for "Chrome" first would misidentify every Edge user as a Chrome user. The same problem applies to Opera (contains Chrome and Safari), Samsung Internet, and most bots (many announce themselves with a Mozilla/5.0 prefix indistinguishable from a real browser at a glance). This parser checks the most specific, most distinguishing tokens first — bots before browsers, Edge and Opera before Chrome, Chrome before Safari — for exactly this reason.
What this is useful for, and its real limits#
Reading server logs to understand real traffic, debugging a bug that only reproduces on one browser or OS, or confirming whether a hit in an access log was a real visitor or a crawler are the practical uses this tool is built for. What it cannot do is guarantee accuracy against a User-Agent that has been deliberately spoofed — a browser extension, a scraper, or a security scanner can set this header to whatever string it wants, and nothing about HTTP prevents that. Treat a parsed User-Agent as a strong hint from a cooperative client, not a verified fact.