Proxy Protocols Explained: HTTP, HTTPS, SOCKS4, and SOCKS5
Understand HTTP, HTTPS, SOCKS4 and SOCKS5 proxies, including tunneling, encryption, UDP, authentication, setup and troubleshooting.
Short answer: HTTP proxies understand HTTP and can forward requests or create a tunnel with CONNECT. HTTPS is HTTP protected by TLS to the origin; it is not a separate proxy protocol. SOCKS4 is a legacy TCP relay, while SOCKS5 adds UDP, domain-name and IPv6 addressing, and negotiated authentication. None of HTTP, SOCKS4 or SOCKS5 encrypts payloads by itself.
Choose an HTTP proxy for HTTP-aware policy, headers, caching or request logs. Use HTTP CONNECT when TLS must pass through an HTTP proxy. Choose SOCKS5 for arbitrary TCP, UDP, domain names or IPv6. Use SOCKS4 only when a legacy endpoint requires it.
HTTP, HTTPS and SOCKS: what each term means
HTTP proxy
An HTTP proxy receives an HTTP request, can inspect methods, headers and the target, then forwards it. For an HTTPS URL, clients normally send CONNECT host:443. After a successful 2xx response, the connection becomes a byte tunnel and the client performs TLS with the origin through it. RFC 7231 §4.3.6 defines CONNECT as establishing a tunnel and then restricting the proxy to blind forwarding.
HTTPS
https:// means HTTP over TLS. TLS authenticates the origin with its certificate and provides confidentiality and integrity for that connection (RFC 9110). HTTPS does not guarantee that the client-to-proxy hop is encrypted or that proxy credentials are protected.
SOCKS4
SOCKS4 is an older TCP-oriented relay. It does not parse HTTP semantics and has no native UDP operation. It is mainly used for compatibility with older clients and servers. SOCKS4 provides no encryption.
SOCKS5
SOCKS5 is an application-layer shim between an application and transport. Negotiation selects an authentication method, then a request asks the proxy to CONNECT, BIND or create a UDP ASSOCIATE. It supports IPv4, domain names and IPv6. The conventional service port is TCP 1080, although deployments may choose another. SOCKS5 is a relay protocol, not an encryption scheme.
Comparison table
| Protocol | Understands | Transport | Addressing and auth | Encryption |
|---|---|---|---|---|
| HTTP proxy | HTTP methods, headers and responses | Forwards HTTP; CONNECT creates a tunnel | Proxy auth headers and 407 challenges | Plain HTTP is exposed; HTTPS payload can remain end-to-end TLS through CONNECT |
| HTTPS | HTTP inside TLS | TCP/TLS to origin, possibly via CONNECT | Origin certificate; proxy auth is separate | Protects the TLS segment only |
| SOCKS4 | Nothing about HTTP | TCP relay | Legacy, limited authentication | None inherent |
| SOCKS5 | Nothing about HTTP | TCP CONNECT, BIND, UDP ASSOCIATE | IPv4/domain/IPv6; negotiated methods | None inherent; username/password is cleartext in subnegotiation |
How HTTPS through an HTTP proxy works
- The client opens a TCP connection to the proxy.
- It sends
CONNECT example.com:443, optionally with proxy credentials. - The proxy allows or rejects the authority and returns 2xx on success. A 407 response means proxy authentication is required (RFC 9110).
- The client and origin complete TLS through the tunnel. The proxy can see destination authority, timing and volume, but need not parse the encrypted body.
Restrict CONNECT to required ports and destinations. RFC 7231 warns that unrestricted CONNECT, including to SMTP port 25, can turn a proxy into an abuse relay.
SOCKS5 negotiation and UDP
- The client sends a version and list of supported authentication methods.
- The server selects one;
0xFFmeans no offered method is acceptable. - If username/password is selected, the client performs RFC 1929 subnegotiation.
- The client sends a relay request with an operation and address type.
Use CONNECT for a TCP stream, BIND for protocols requiring an inbound connection, and UDP ASSOCIATE for datagrams. UDP behavior depends on the client, proxy and network path. Test fragmentation, idle timeouts and replies for your application. See RFC 1928.
Authentication and encryption boundaries
HTTP proxy authentication uses 407 and Proxy-Authenticate/Proxy-Authorization. It authenticates to the proxy, not the origin. SOCKS5 can negotiate no authentication, GSSAPI or username/password (RFC 1928). RFC 1929 states that the username/password request carries the password in cleartext and is not recommended where sniffing is practical (RFC 1929). Use a separately protected channel or stronger method when credentials could be intercepted.
Document where DNS is resolved, where TLS terminates, whether the proxy logs destinations, how credentials are stored, and which destinations and ports are allowed.
Runnable examples
cURL
# HTTP origin through HTTP proxy
curl --proxy http://proxy.example:8080 http://example.com/
# HTTPS origin through HTTP CONNECT
curl --proxy http://proxy.example:8080 https://example.com/
# Authenticated HTTP proxy
curl --proxy http://proxy.example:8080 --proxy-user "$PROXY_USER:$PROXY_PASS" https://example.com/
# SOCKS5 with proxy-side DNS
curl --socks5-hostname socks.example:1080 https://example.com/
# SOCKS5 credentials
curl --socks5-hostname "$SOCKS_USER:$SOCKS_PASS@socks.example:1080" https://example.com/
# SOCKS4
curl --socks4 socks4.example:1080 https://example.com/
--socks5-hostname resolves the hostname through SOCKS5; --socks5 resolves locally. Keep secrets out of shell history and process listings.
Python
import os
import requests
proxies = {
'http': os.environ['HTTP_PROXY_URL'],
'https': os.environ['HTTPS_PROXY_URL'],
}
r = requests.get('https://example.com/', proxies=proxies, timeout=(10, 30))
r.raise_for_status()
print(r.status_code, len(r.content))
# pip install requests[socks]
socks = {
'http': 'socks5h://user:pass@socks.example:1080',
'https': 'socks5h://user:pass@socks.example:1080',
}
r = requests.get('https://example.com/', proxies=socks, timeout=(10, 30))
r.raise_for_status()
print(r.url)
Node.js
import { HttpsProxyAgent } from 'https-proxy-agent';
const proxy = process.env.HTTPS_PROXY_URL;
const agent = new HttpsProxyAgent(proxy);
const res = await fetch('https://example.com/', { dispatcher: agent });
if (!res.ok) throw new Error(`HTTP ${res.status}`);
console.log((await res.text()).length);
Install with npm install https-proxy-agent. Native Node.js fetch does not automatically honor every proxy environment variable. SOCKS requires a SOCKS-capable agent such as socks-proxy-agent.
Choosing a protocol
| Requirement | Best fit | Reason |
|---|---|---|
| Header filtering, URL policy, caching or HTTP logs | HTTP proxy | The proxy understands HTTP |
| TLS web traffic through an HTTP gateway | HTTP CONNECT | Origin TLS remains end-to-end through a controlled tunnel |
| Arbitrary TCP, UDP, IPv6 or proxy-side DNS | SOCKS5 | Protocol-agnostic relay with those operations |
| Legacy TCP-only integration | SOCKS4 | Compatibility with an older endpoint |
Operational checklist
- Allow-list CONNECT ports and destinations.
- Decide whether DNS must stay inside the proxy.
- Verify origin certificates independently of proxy authentication.
- Rotate credentials and keep them out of URLs and logs.
- Set bounded connect and read timeouts.
- Retry only idempotent operations.
- Confirm UDP support, MTU behavior and idle limits.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| 407 Proxy Authentication Required | Missing or rejected credentials | Use the required scheme and check the account. |
| CONNECT refused or 403 | Destination or port is not allow-listed | Request the exact host/port and narrow the allow-list. |
| TLS certificate error | Origin certificate failure or interception | Inspect the certificate chain and trust store. |
| DNS leak | Client resolved locally | Use SOCKS5 hostname mode or configure the intended resolver. |
| SOCKS method 0xFF | No offered method is accepted | Enable the method required by the server. |
| UDP is intermittent | NAT, fragmentation or idle timeout | Use small datagrams, keep the association alive and test every hop. |
| HTTP works but HTTPS fails | CONNECT is unsupported or port 443 is blocked | Use a CONNECT-capable configuration and allow 443. |
Performance, reliability and cost
Proxy distance, congestion, TLS handshakes, DNS placement and origin time usually matter more than protocol overhead. Reuse connections, set bounded timeouts, and record connect, tunnel, TLS and response timings separately. Retries can duplicate non-idempotent requests. A proxy can fail independently of the origin, so health checks should exercise the complete path.
Costs depend on the operator, traffic volume, egress and support terms. The standards do not define pricing or a universal speed ranking.
Or skip the browser setup
If your goal is a clean screenshot, ScreenshotNeo is a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF. See the API docs.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Cookie banners, newsletter popups and chat widgets are removed before capture. Bot checks, blank pages and failed loads are never billed, and response headers identify the page verdict and billing result. MCP tools include take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
FAQ
Is an HTTPS proxy the same as HTTPS?
No. HTTPS describes HTTP over TLS to an origin. Verify what a provider means by HTTPS proxy.
Does SOCKS5 encrypt traffic?
No. SOCKS5 relays bytes; use TLS or another encryption layer.
Should I choose SOCKS4 or SOCKS5?
Choose SOCKS5 unless a legacy system requires SOCKS4.
Can an HTTP proxy see HTTPS pages?
With CONNECT, it sees metadata while the origin payload remains inside TLS. If it terminates TLS, it can inspect decrypted traffic.
Where should DNS resolution happen?
Use proxy-side DNS when client DNS must stay private or private names are only resolvable there. Confirm the client option you use.


