Testing a proxy before production use
Updated 2 min read
Run four checks before a proxy goes into a pipeline: the request uses the proxy, HTTPS tunnels through it, the exit behaves as expected, and the target sees nothing that names a proxy. Each takes one command. For a proxy set to IP allowlist, use http://HOST:PORT without credentials in each command.
Step 1: the request uses the proxy
Compare your direct address with the address seen through the proxy:
curl -sS https://api.ipify.org; echo
curl -sS -x "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org; echo
Expected result: two different addresses. If both lines match, the client bypassed the proxy. Check for a NO_PROXY rule, and whether the client needs the proxy set separately for https.
Step 2: HTTPS tunnels through it
curl -sv -o /dev/null -x "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org 2>&1 | grep -E '^(> CONNECT|< HTTP)'
Expected result: a CONNECT line, then a 200 from the proxy, then the site's own status. A 407 before the tunnel is a credentials problem; see Diagnosing proxy status codes 407 and 403.
Step 3: the exit behaves as expected
Repeat the lookup five times:
for i in 1 2 3 4 5; do curl -sS -x "http://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.org; echo; done
| Product and setting | Expected result |
|---|---|
Residential or mobile (coming soon) |
Usually a different address on most lines |
ISP or datacenter |
Always the same address, the one shown on the proxy's page |
Step 4: what the target sees
Open the proxy checker in a browser that uses the proxy. It reports the exit address, the network that announces it, whether WebRTC exposes a second address, and whether the request carries headers that name a proxy. The page also gives a curl command that reports the exit address and any proxy-revealing headers from a terminal.
The dashboard has its own checks as well. Test this proxy on a proxy's page dials it the way your client would. Tools > Proxy checker tests many at once: My proxies picks from the account, and Any proxy list tests a list you paste. Neither touches your balance.
Keep these commands as a smoke test and run them again whenever something upstream changes.