Skip to content
RU
← All articles

What Is a Proxy Server? How It Works, Types and Proxy vs VPN

A proxy server in a rack between two switches and proxy settings on a laptop

The short answer to what is a proxy server: an intermediary that sits between a client and the servers it talks to. The client sends its request to the proxy, which makes it on the client's behalf and relays the response. The destination sees the proxy's IP, and the proxy can filter, cache, log or modify the traffic.

What is a proxy server, in plain terms

"Proxy" means someone authorised to act for another person — voting by proxy, for example. A proxy server is exactly that for network traffic. Instead of your laptop opening a connection to a website, it asks the proxy to fetch the page. The proxy opens its own connection, receives the response and hands it back. From the website's point of view, the proxy was the visitor.

That single position in the middle is what makes proxies useful. Everything passing through one point can be allowed or denied, stored for reuse, recorded, or rewritten. It is also what makes them sensitive: whoever runs the proxy sees which hosts you connect to, and anything you send without encryption.

How a proxy handles a request

A client configured to use a proxy connects to the proxy's address and port rather than to the destination. What happens next depends on the protocol.

Plain HTTP: the proxy does the fetching

For unencrypted HTTP, the client sends the full URL in the request line — the so-called absolute form — so the proxy knows where to go:

GET http://example.com/docs HTTP/1.1
Host: example.com

The proxy parses the request, opens its own connection to example.com and forwards it. Because it reads the whole exchange, it can cache the response, strip headers, block the URL, or inject content.

HTTPS: the proxy opens a tunnel

For TLS traffic the proxy cannot read the payload, so the client asks for a raw tunnel using the CONNECT method defined in RFC 9110:

CONNECT example.com:443 HTTP/1.1
Host: example.com:443

HTTP/1.1 200 Connection established

After the 200 response, the proxy simply shuttles bytes in both directions. The TLS handshake happens end to end between the browser and the site, so the proxy learns the hostname and port but not the paths, form data or cookies. You can watch this happen with curl:

curl -v -x http://proxy.example.net:3128 https://example.com/

The verbose output shows the CONNECT request to the proxy, the 200 reply, and only then the TLS handshake with example.com.

The exception is a TLS-inspecting gateway, common in corporate networks. It terminates TLS itself and presents a certificate issued by the organisation's own root CA, which has been pushed to managed devices. If the certificate for a public site shows your employer as the issuer, your HTTPS traffic is being decrypted and re-encrypted by a proxy.

Authentication

A proxy that requires credentials answers the first request with 407 Proxy Authentication Required and a Proxy-Authenticate header; the client retries with Proxy-Authorization. Note the difference from 401, which comes from the website itself.

Forward proxy vs reverse proxy

The word "proxy" covers two roles that sit at opposite ends of the connection.

A forward proxy acts for clients. Users or administrators point browsers and operating systems at it, and it reaches out to the internet on their behalf — a company gateway running Squid is the textbook case.

A reverse proxy acts for servers. Visitors never configure it and usually do not know it exists: they connect to a domain, and nginx, HAProxy or a CDN edge accepts the request and passes it to one of the application servers behind it. The mechanics are covered in detail in our guide to reverse proxies.

AspectForward proxyReverse proxy
RepresentsClientsOne or more origin servers
Configured byThe user or network adminThe site operator
Visible to the clientYes, it is set in proxy settingsNo, the client only sees a hostname
Typical jobsEgress control, logging, caching, malware scanningTLS termination, load balancing, caching, shielding the app
Common softwareSquid, Privoxy, 3proxynginx, HAProxy, Traefik, Envoy, CDNs

Types of proxy servers

HTTP proxies

Speak HTTP, fetch plain-HTTP requests themselves and tunnel HTTPS with CONNECT. "HTTPS proxy" is an ambiguous label: vendors use it both for an HTTP proxy that supports CONNECT and for a proxy you reach over a TLS-encrypted connection, where even the hop between you and the proxy is protected.

SOCKS proxies

SOCKS works below HTTP and relays arbitrary TCP connections, which makes it usable for SSH, mail clients or database tools. SOCKS5, specified in RFC 1928, added authentication, IPv6, UDP relaying and the option to pass a hostname to the proxy instead of an IP. That last point matters for DNS: in curl, --socks5 resolves the name locally, while --socks5-hostname lets the proxy resolve it.

Transparent (intercepting) proxies

Nothing is configured on the client. A router or firewall redirects outbound traffic — typically port 80 — into the proxy. ISPs, hotel and airport Wi-Fi with a login page, and school networks use this approach. You usually notice one only through a block page or a Via header in responses.

"Anonymous" and "elite" proxies

These labels come from proxy sellers, not from any standard. They describe which headers the proxy adds: a "transparent" one in this sense forwards your IP in X-Forwarded-For, an "anonymous" one hides it but announces itself via Via, and an "elite" one adds neither. None of this hides you from the proxy operator.

Common proxy ports

PortUsually
3128Squid's default, widely used by corporate HTTP proxies
8080Generic alternative HTTP port, common for proxies and dev tools
1080SOCKS, the port IANA registers for the protocol
8118Privoxy's default
8888Debugging proxies such as Fiddler and Charles

Ports are conventions, not guarantees — any service can listen anywhere. If you need to find out what is actually listening on a machine, see how to find a server's port.

What proxies are used for

  • Egress control. Servers in a locked-down network reach package mirrors and APIs only through a proxy with an allowlist, so a compromised host cannot call arbitrary addresses.
  • Caching. A shared cache serves repeated downloads — OS updates, container layers, installers — from the local network.
  • Policy and audit. Organisations log outbound requests and enforce acceptable-use rules at one point.
  • Security scanning. Gateways inspect downloads for malware before they reach endpoints.
  • Development and debugging. mitmproxy, Fiddler and Charles let you inspect, replay or rewrite an app's HTTP traffic and simulate slow networks.
  • Serving websites. In the reverse role, proxies absorb traffic, terminate TLS and keep application servers off the public internet.

Proxy vs VPN

AspectProxyVPN
LayerApplication (HTTP or SOCKS)Network (IP packets)
What goes through itOnly apps configured to use itAll device traffic, unless split tunnelling is set
Encryption to the intermediaryUsually none, unless it is a TLS proxyAlways; it is the core of the protocol
DNS lookupsDepends on client and proxy typeNormally sent through the tunnel
SetupHost and port in settings, or a PAC fileClient software and a profile
Typical useGateways, caching, debuggingRemote access to private networks, site-to-site links

The key takeaway: a plain proxy adds no encryption of its own. HTTPS sites remain protected by their own TLS, but plain HTTP through an unencrypted proxy travels in the clear to whoever runs it.

Proxy settings explained

Operating systems, phones, smart TVs and routers use much the same fields:

  • Proxy host — hostname or IP of the proxy, such as proxy.corp.example.
  • Port — where the proxy listens, such as 3128.
  • Bypass list — destinations reached directly, usually local addresses and intranet domains.
  • Script address — the URL of a PAC (proxy auto-config) file, a JavaScript function that picks a route per URL.
  • Automatically detect settings — discovering a PAC file via WPAD on the local network.

A minimal PAC file looks like this:

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:3128; DIRECT";
}

On Android the option sits in the Wi-Fi network's advanced settings as Proxy: None, Manual or Proxy Auto-Config. At home, None is almost always correct; a stale proxy entry is a classic cause of "connected, but nothing loads".

How to tell whether you are using a proxy

Windows

Open Settings → Network & internet → Proxy to see automatic detection, setup script and manual proxy state. Services and some system components use the separate WinHTTP configuration:

netsh winhttp show proxy

"Direct access (no proxy server)" means WinHTTP goes straight out. The per-user settings used by browsers live in the registry:

Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings' |
  Select-Object ProxyEnable, ProxyServer, AutoConfigURL

macOS

System Settings → Network → your connection → Details → Proxies. From Terminal, scutil --proxy prints the effective configuration; look for HTTPEnable : 1, HTTPSEnable : 1, SOCKSEnable : 1 or ProxyAutoConfigEnable : 1. Per interface: networksetup -getwebproxy Wi-Fi.

Linux and command-line tools

env | grep -i proxy

curl, wget, apt, pip and most CLI tools honour http_proxy, https_proxy and no_proxy. A variable left over in ~/.bashrc or /etc/environment is a frequent reason why a script fails while the browser works. On GNOME, gsettings get org.gnome.system.proxy mode returns 'none' when no desktop proxy is set.

Browsers

Chrome and Edge follow the operating system; Firefox has its own panel under Settings → General → Network Settings. If the address websites report differs from your router's public IP, something is relaying your traffic — our guide on finding your IP address shows how to compare the two.

Proxies from the server side

Behind a reverse proxy or CDN, your application sees the proxy's address as the client IP. The original address travels in headers: the de facto X-Forwarded-For, or the standard Forwarded header from RFC 7239. Intermediaries that modify messages also add Via.

These headers are only as trustworthy as whoever set them. Any client can send X-Forwarded-For: 203.0.113.9; an application that blindly takes the first entry lets visitors choose their own IP for rate limits and logs. In nginx, the realip module restores the client address only from proxies you list:

set_real_ip_from 10.0.0.0/8;
real_ip_header X-Forwarded-For;
real_ip_recursive on;

The header format and its pitfalls are covered in our X-Forwarded-For guide.

The other server-side risk is an accidental open proxy. A Squid or SOCKS service reachable from the internet without authentication will be found by scanners and used to relay spam and attacks, with complaints landing on your IP. Squid evaluates http_access rules top to bottom, so the list should end with a catch-all deny:

http_port 3128
acl localnet src 10.0.0.0/8
http_access allow localnet
http_access deny all

More on why listening services should not face the internet unnecessarily in open ports and server security.

Common proxy errors

  • ERR_PROXY_CONNECTION_FAILED (Chrome) — the configured proxy did not accept a connection: wrong host or port, or the proxy is down.
  • ERR_TUNNEL_CONNECTION_FAILED — the proxy refused or failed to open a CONNECT tunnel to the destination.
  • 407 Proxy Authentication Required — the proxy, not the site, wants credentials.
  • 502 / 504 from the proxy — the proxy could not get a timely answer from the destination. Check who generated the error page; Squid signs its own.

How to check

Use the IP lookup to see which address websites attribute to you and which network it belongs to. On your own servers, run the port scanner against 3128, 8080 and 1080 to make sure no proxy is exposed. The HTTP header checker shows whether a site sits behind a reverse proxy or CDN through headers such as Via, Server and cache status fields.

Frequently asked questions

What is a proxy port?

The TCP port the proxy listens on, entered together with the host, for example proxy.corp.example:3128. Common values are 3128 and 8080 for HTTP proxies and 1080 for SOCKS.

Does a proxy encrypt my traffic?

Not by itself. HTTPS connections stay encrypted end to end, but the proxy still sees which hosts you contact, and plain HTTP is readable unless the connection to the proxy uses TLS.

Why is everything slower through a proxy?

Each request takes an extra hop, and a distant or overloaded proxy adds latency. Measure the round trip to the proxy itself with ping against its address and compare it with the latency to the destination.

Is a reverse proxy a security layer?

It helps — it hides origin addresses and can enforce limits — but only if the origin refuses direct connections. An origin reachable by IP can be attacked around the proxy.

Should I enable a proxy on my phone or TV?

Only if a network administrator gave you specific settings. Otherwise leave it set to None; a wrong entry breaks connectivity.

Check your website right now

Check if your site is reachable →
More articles: Networking
Networking
Cloudflare Blocked in Russia? Why Sites Fail and How to Fix It
20.07.2026 · 2 945 views
Networking
Your Site Is Blocked in Russia: Owner's Guide
13.07.2026 · 1 143 views
Networking
ERR_CONNECTION_TIMED_OUT: Fix It in Chrome, Windows and Android
23.06.2026 · 1 041 views
Networking
IP Geolocation Accuracy: How It Works and Where It Fails
11.03.2026 · 1 019 views