ScreenshotNeo

BlogGuides

What Is a Proxy Server and How Does It Work?

A proxy server mediates traffic between a client and another server. Learn how forward and reverse proxies work, what HTTPS reveals, and how proxies compare with VPNs.

By the ScreenshotNeo team4 October 20268 min read

A proxy server is an intermediary that receives a request from a client and communicates with another server on the client’s behalf. It can forward, modify, block, authenticate, log, cache, or route traffic, depending on its configuration. A forward proxy represents clients; a reverse proxy sits in front of destination servers and mediates incoming requests.

A proxy may make a destination see the proxy’s IP address, but that alone does not make the client anonymous. For HTTPS, a proxy that only tunnels the connection generally relays encrypted data; a proxy configured to terminate TLS can inspect traffic. These details depend on the proxy and how it is set up.

1. What a proxy server does

In a direct connection, a client such as a browser sends a request to a destination server and receives its response. With a proxy, the client’s request goes through an intermediary. The proxy decides what to do under its policy: it may connect to the destination, return a cached response, change or block the request, require authentication, or record activity.

The proxy may be configured on a device, in an application, or in a network. The term describes a role in the request path, not one specific protocol or privacy guarantee. The exact behavior depends on the proxy software, its configuration, and the traffic it handles. [MDN: Proxy servers and tunneling] [Microsoft Learn: Proxy server overview]

2. How a forward proxy works

A forward proxy acts for a client or group of clients accessing external destinations. A typical request follows these steps:

  1. The client is configured to use a proxy, or an application explicitly sends its request to one.
  2. The proxy applies its rules. It may authenticate the client, allow or deny the destination, log the request, or check its cache.
  3. If needed, the proxy connects to the destination server and sends the request onward.
  4. The destination responds to the proxy, which relays the response to the client. If a suitable cached response exists, the proxy may return that instead.

Organizations commonly use forward proxies to mediate outbound access and apply network controls. A forward proxy can also pass client details in headers, so the destination may learn information about the original client even if the connection comes from the proxy’s address.

3. How a reverse proxy works

A reverse proxy represents a server or service. It receives requests from clients and selects or mediates access to one or more backend servers. The client addresses the service through the proxy rather than connecting directly to a backend.

Reverse proxies can distribute requests among backend servers, cache static content, and compress responses. They can also keep backend addressing out of the client-facing request path. That arrangement can be useful, but hiding backend addresses alone is not a complete security strategy. [MDN: Proxy servers and tunneling]

4. Forward proxy vs. reverse proxy

Question Forward proxy Reverse proxy
Whose side does it represent? A client or group of clients A destination server or backend service
Where does it sit? Between clients and external destinations In front of one or more backend servers
Typical functions Mediate outbound access and apply controls Distribute requests, cache static content, or compress responses
Important caveat Headers may reveal original client information Concealing backend addressing is not a complete security measure

5. What happens when a proxy handles HTTPS?

HTTPS protects content with TLS between the client and the destination when the proxy is only relaying a tunnel. An HTTP proxy commonly establishes that tunnel with the CONNECT method. The client asks the proxy to connect to a host and port; after a successful response, the proxy relays bytes in both directions. The client and destination then negotiate TLS through the tunnel.

In that tunnel setup, the proxy handles connection metadata, such as the requested host and connection timing, but does not automatically read the encrypted page contents. A proxy deliberately configured to terminate TLS can inspect traffic instead, subject to its certificate and trust configuration. Therefore, whether a proxy can read HTTPS content depends on whether TLS remains end to end or is terminated at the proxy. [MDN: CONNECT request method]

Client                         HTTP proxy                         Website
  |                                |                                  |
  |--- CONNECT example.com:443 --->|                                  |
  |<---------- 2xx ----------------|                                  |
  |==== TLS handshake and encrypted data through tunnel =============>|
  |<=========== encrypted response relayed ===========================|

MDN describes CONNECT as requesting that a proxy establish a tunnel to a destination and, if successful, blindly forward data in both directions until the tunnel closes. A proxy operator should restrict allowed destinations or ports; an unrestricted tunnel can be abused to reach unsafe or unintended services. [MDN: CONNECT request method]

6. Does a proxy hide your IP address?

A proxy can cause a destination to see the proxy’s network address as the source of a connection. But that does not prove the original client is anonymous or private:

  • Headers can disclose client details. Headers such as Forwarded or X-Forwarded-For can carry the original client address.
  • The proxy operator may see metadata. Depending on the service and configuration, the operator may process destination addresses, timing, and other connection details.
  • Not all traffic necessarily uses the proxy. An application or device may send some requests directly.
  • TLS handling matters. A tunnel that preserves end-to-end TLS has different visibility from a proxy that terminates TLS.

Evaluate who operates the proxy, what it logs, which traffic is routed through it, whether identifying headers are forwarded, and how TLS is handled. Privacy depends on these details, not on the word “proxy.” [MDN: Proxy servers and tunneling] [MDN: Forwarded header]

7. Is a proxy the same as a VPN?

No single distinction applies to every product called a proxy or VPN. Compare the actual setup: which traffic is routed, what is encrypted, what the intermediary can see, and who operates it. Some proxy arrangements mediate selected application requests, while VPN setups commonly route network traffic through a tunnel. These categories can overlap: the IETF specifies tunneling IP through an HTTP server acting as an IP proxy, with uses that include remote-access and site-to-site VPNs. [IETF RFC 9484]

Question to check Why it matters
Which applications or traffic are routed? A proxy setting may apply only to configured clients; another tunnel may carry broader network traffic.
Where does encryption begin and end? A tunnel and end-to-end HTTPS protect different parts of a request path.
What can the intermediary see? Visibility depends on whether traffic is tunneled or decrypted and on connection metadata.
Who operates the service? The operator’s access and logging practices affect privacy.

8. Common proxy problems and fixes

Symptom Likely cause What to check
Connection refused or proxy unavailable The proxy host or port is wrong, the service is down, or a firewall blocks access. Verify the configured address and port, confirm the proxy is reachable, and check network rules.
Authentication required or rejected Credentials are missing, expired, or not accepted by this proxy. Check the account and authentication method with the proxy administrator; avoid putting credentials in shared logs or URLs.
Some sites work while others fail Proxy policy, destination restrictions, DNS behavior, or CONNECT port restrictions may differ by site. Check the proxy’s allowlist and supported ports, then compare a permitted destination with the failing one.
HTTPS certificate warning TLS may be intercepted, or the client may not trust the configured inspection certificate. Confirm whether TLS inspection is intended and check the organization’s approved certificate setup. Do not bypass a certificate warning without understanding its cause.
The destination still identifies the client The proxy may forward identifying headers, or the request may bypass the proxy. Inspect request routing and forwarded headers; ask the operator how client information is handled.
Unexpected stale content A caching proxy may return a stored response. Check cache policy and freshness behavior with the proxy administrator, especially for personalized or changing content.

9. Performance, reliability, and cost considerations

A proxy adds an intermediary hop, so it can add latency. Caching can avoid a trip to the origin for eligible content, and a reverse proxy can distribute requests among backends; either can improve delivery in an appropriate deployment. Results depend on network distance, cache hit rate, proxy capacity, origin health, and configuration. No one performance outcome applies to all proxies.

Reliability depends on the proxy and the systems around it. A forward proxy can become a dependency for the clients configured to use it. A reverse proxy can mediate access to several backends, but its availability and routing configuration matter. Plan monitoring, capacity, access rules, and failure behavior for the specific deployment.

Cost also depends on the deployment model: a managed service may charge for usage or capacity, while a self-managed proxy requires infrastructure and operational work. The sources for this guide do not establish universal pricing or performance figures, so compare the terms and measured behavior of the specific service or deployment.

10. How to choose or configure a proxy safely

  1. Identify the role. Decide whether clients need an outbound forward proxy or a service needs an inbound reverse proxy.
  2. Define the traffic scope. Specify which clients, applications, destinations, and ports should use it.
  3. Set access controls. Require appropriate authentication and restrict destinations and CONNECT ports to intended use.
  4. Decide on TLS behavior. Be explicit about whether HTTPS is tunneled end to end or deliberately terminated for inspection.
  5. Review headers and logs. Determine whether client-identifying headers are forwarded and what connection data the operator retains.
  6. Test expected failure cases. Check denied destinations, unavailable proxy behavior, authentication failures, and cache behavior where applicable.
  7. Measure the actual path. Evaluate latency and reliability under the workload the proxy will serve rather than assuming a universal benefit.

11. ScreenshotNeo for website screenshots

If you arrived here while evaluating how to capture website pages, ScreenshotNeo is a website screenshot API and MCP server for developers. A proxy mediates network requests; ScreenshotNeo’s documented product is for returning website screenshots or PDFs from a URL. It is made by Yorker Media. See ScreenshotNeo and the API documentation.

12. FAQ

Can a proxy server respond without contacting the destination?

Yes. A proxy may return a cached response or block a request according to its policy instead of contacting the destination for that request.

Does every proxy change the request?

No. A proxy can relay traffic without changing it, or it may modify, filter, authenticate, cache, or log traffic. Its configuration determines its behavior.

Can a reverse proxy hide a backend server?

It can keep backend addressing out of the client-facing path. That alone does not provide complete security; deployment and access controls still matter.

Or skip the browser setup

For a website screenshot, ScreenshotNeo returns an image or PDF with one GET request. This cURL example saves a WebP screenshot:

curl -G "https://api.screenshotneo.com/v1/shot" \
  -d access_key=YOUR_API_KEY \
  --data-urlencode url=https://stripe.com \
  -o shot.webp

Equivalent Python:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

Equivalent Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
const bytes = new Uint8Array(await res.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', bytes));

ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot. Bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for free and get 1,000 screenshots a month with no card.