SOCKS Proxy: What It Is, How SOCKS5 Works, and SOCKS5 vs HTTP Proxies

Explainer ยท Last reviewed 28 September 2026 ยท 11 min read

A SOCKS proxy is a proxy that relays raw network connections instead of web requests, so it can carry almost any kind of TCP traffic, not only HTTP. SOCKS5, the current version, adds username and password authentication, IPv6, domain-name addressing and UDP support. This guide explains how a SOCKS proxy works, SOCKS4 vs SOCKS5, how SOCKS5 compares with an HTTP proxy, its benefits and drawbacks, and how to use a SOCKS5 proxy in curl, Python and your browser, including with ProxyEmpire residential proxies.

The short version

A SOCKS proxy forwards connections at a lower level than an HTTP proxy, so it works with any application that supports it, not just browsers. Use SOCKS5 when a tool or protocol needs a generic relay, or when you want the proxy to resolve host names for you. For ordinary web scraping and browsing, an HTTP(S) proxy works just as well. Neither encrypts your traffic on its own.

What Is a SOCKS Proxy?

A general-purpose relay

SOCKS, short for “Socket Secure”, is a protocol that lets a client ask a proxy server to open a network connection on its behalf. Once the proxy has connected to the destination, it simply passes bytes back and forth. It does not read or rewrite the application data, so it does not care whether that data is a web page, a chat message or a file transfer.

That is the key difference from an HTTP proxy, which understands web requests and responses. SOCKS works one layer lower: it relays the connection, and the application on each end speaks whatever protocol it likes over it.

An HTTP proxy understands the conversation. A SOCKS proxy just carries it.

How SOCKS5 Works

A short handshake, then raw data

The SOCKS5 protocol is defined in RFC 1928. A connection goes through four steps:

  1. Greeting. The client connects to the proxy and lists the authentication methods it supports.
  2. Method selection and authentication. The proxy picks one. With username and password, defined in RFC 1929, the client then sends its credentials and the proxy accepts or rejects them.
  3. Request. The client asks the proxy to CONNECT to a destination, given as an IPv4 address, an IPv6 address or a domain name, plus a port. SOCKS5 also defines BIND for incoming connections and UDP ASSOCIATE for UDP traffic.
  4. Reply and relay. The proxy connects and answers with a reply code; from then on, data flows through unchanged.
The SOCKS5 exchange, simplified
client                          SOCKS5 proxy                    website
  | -- hello: methods [user/pass] --> |                             |
  | <-- use user/pass --------------- |                             |
  | -- username + password ---------> |                             |
  | <-- success ---------------------- |                             |
  | -- CONNECT example.com:443 -----> | -- TCP connect -----------> |
  | <-- reply 0x00 (succeeded) ------- |                             |
  | <================ encrypted TLS data relayed ================> |

If the proxy cannot complete the request, the reply code says why, for example “connection refused” or “host unreachable”. Our proxy error codes guide lists every SOCKS5 reply code.

SOCKS4 vs SOCKS4a vs SOCKS5

Use SOCKS5 unless a tool forces otherwise
SOCKS4SOCKS4aSOCKS5
TCP connectionsYesYesYes
UDPNoNoYes (UDP ASSOCIATE), where the proxy supports it
IPv6 destinationsNoNoYes
Domain names resolved by the proxyNoYesYes
Password authenticationNo (user ID only)No (user ID only)Yes (RFC 1929), plus GSS-API (RFC 1961)

A note on UDP: the protocol allows a client to ask for a UDP relay, which matters for things like DNS queries, voice and some games. Support is optional, though, and many commercial proxy networks relay TCP only, because nearly all web traffic runs over TCP. If your use case depends on UDP, confirm support with the provider before you buy; ProxyEmpire relays TCP traffic only.

SOCKS4 and 4a are legacy. Every modern tool that supports SOCKS supports SOCKS5, and paid proxy services use it because it supports authentication.

SOCKS5 vs HTTP Proxies

Different layers, similar results for the web
SOCKS5 proxyHTTP(S) proxy
What it relaysAny TCP connection, and UDP where supportedHTTP requests; HTTPS through CONNECT tunnels
Understands web trafficNoYes, can read and modify plain HTTP
EncryptionNone of its ownNone of its own for the proxy hop; HTTPS sites stay encrypted by TLS
AuthenticationUsername and password in the handshakeProxy-Authorization header
DNSCan let the proxy resolve names (socks5h)Proxy resolves names for tunnelled requests
SupportMany apps, some browsers, all major HTTP librariesAlmost everything that speaks HTTP
Best forNon-HTTP apps and tools that prefer SOCKSWeb scraping, browsers, most SEO and data tools

For HTTPS websites the difference is small in practice: in both cases your TLS connection runs end to end between your client and the website, and the proxy sees only the destination host and port. Choose the protocol your tool supports best. With ProxyEmpire, HTTP and SOCKS5 use the same host, port and credentials, so switching is a matter of changing the scheme.

Benefits and Drawbacks of a SOCKS Proxy

What it does well, and what it doesn’t

Benefits

  • Protocol-agnostic. Carries any TCP-based application protocol, not just web traffic.
  • Remote DNS. The proxy can resolve host names, so your own DNS server does not see which sites you connect to.
  • No content changes. The proxy does not rewrite headers or content.
  • Authentication. SOCKS5 supports username and password, so paid proxies stay private to you.

Drawbacks

  • No encryption. The relay does not encrypt anything by itself; use HTTPS or another encrypted protocol inside it.
  • Uneven support. Some applications support only HTTP proxies, and some browsers do not support SOCKS5 with a username and password.
  • UDP depends on the provider. The protocol supports UDP, but many services, ProxyEmpire included, relay TCP only.
  • Port and site rules still apply. ProxyEmpire opens destination ports 80 and 443 by default and blocks banking, payment and government sites on every product.

When to Use a SOCKS Proxy

Pick it for the tool, not for magic
  • Applications that only speak SOCKS, such as some messaging, automation and desktop tools.
  • Scripts where you want remote DNS, so name resolution happens at the proxy’s location.
  • Tunnelling through SSH to reach services from another network (see below).
  • Tools that route whole connections rather than individual HTTP requests.

For collecting web data, checking prices or search results, and browsing, an HTTP(S) proxy is just as effective and more widely supported. What matters more is the IP type behind the proxy; see our comparison of residential, mobile and datacenter proxies.

Choosing between HTTP and SOCKS5 in practice

Start with the tool. If it offers both, pick the one it documents best, because that is the one its developers test. Libraries such as Python requests and curl support both equally well; many desktop apps list HTTP first and treat SOCKS as an extra. Then think about DNS: if your own resolver should not see the hostnames you visit, choose SOCKS5 with remote resolution. Finally, think about the traffic: if it is not HTTP at all, SOCKS5 is the only option. In every other case, the two behave the same for the website, and the choice of IP, residential, mobile or datacenter, matters far more than the protocol.

Privacy: what the relay can and cannot see

Because a SOCKS relay only forwards bytes, it sees the destination address and port and the size and timing of the traffic, but not the content of encrypted connections. The same is true of an HTTP proxy handling HTTPS through a CONNECT tunnel. The practical privacy difference comes from DNS: with remote resolution, lookups happen at the relay, not on your network. For full-device protection on untrusted networks, a VPN is the better tool; our proxy vs VPN guide explains the trade-offs.

Key takeaways

  • SOCKS relays connections; HTTP proxies understand web requests.
  • SOCKS5 adds authentication, IPv6, domain names and UDP support over SOCKS4.
  • Neither SOCKS nor HTTP proxies encrypt traffic; HTTPS does.
  • Use socks5h when you want the proxy to resolve host names.

How to Use a SOCKS5 Proxy

curl, Python and browsers
curl: SOCKS5 with remote DNS (socks5h)
curl -x socks5h://USERNAME:PASSWORD@v2.proxyempire.io:5000 https://ipinfo.io/json

In curl, the scheme selects the SOCKS version: socks5:// resolves host names on your machine, while socks5h:// lets the proxy resolve them.

Python requests: install the SOCKS extra first
# pip install "requests[socks]"
import requests

PROXY = "socks5h://USERNAME:PASSWORD@v2.proxyempire.io:5000"
r = requests.get("https://ipinfo.io/json",
                 proxies={"http": PROXY, "https": PROXY}, timeout=30)
print(r.json())
  • Firefox has SOCKS settings in its connection settings, including an option to send DNS through the proxy. See our Firefox proxy guide.
  • Chrome accepts SOCKS5 through a command-line flag; for proxies with a username and password, the HTTP endpoint or our free extension is simpler. See Chrome proxy settings.
  • Android: the free ProxyEmpire Proxy Manager app supports SOCKS5 with username and password for any app.
  • Anti-detect and automation tools usually offer a SOCKS5 option next to HTTP; see our integrations page.

A SOCKS Proxy over SSH

Your own private tunnel

If you have SSH access to a server, you can turn it into a personal SOCKS proxy. OpenSSH’s -D option opens a local port that acts as a SOCKS server and sends connections through the encrypted SSH session to the remote machine.

Dynamic port forwarding with OpenSSH
ssh -D 1080 -N user@your-server.example.com
# then point your app at SOCKS5 localhost:1080

This is useful for reaching internal systems or protecting traffic on untrusted Wi-Fi, because the hop from your laptop to the server is encrypted by SSH even when the application inside it is not. Your traffic leaves from the server’s single datacenter IP, so it does not help where you need many or residential IPs.

Troubleshooting SOCKS Proxies

Common problems and fixes
  • Authentication fails: check the username and password, and URL-encode special characters in proxy URLs. Copy them fresh from the dashboard rather than retyping them.
  • “SOCKS connection failed” or “host unreachable”: the proxy could not reach the destination; try another site or a fresh IP.
  • Works with HTTP, not with SOCKS: make sure the tool really speaks SOCKS5, not SOCKS4, and that it supports password authentication.
  • DNS leaks: use socks5h in curl and Python, or the proxy DNS option in your browser.
  • Non-web ports blocked: connections to ports other than 80 and 443 are refused by default at ProxyEmpire.

Use them for lawful purposes and within each website’s terms.

SOCKS Proxy FAQ

Straight answers
What is a SOCKS proxy?

A proxy that relays network connections for any application that supports it, instead of handling only web requests like an HTTP proxy.

What is the difference between SOCKS4 and SOCKS5?

SOCKS5 adds username and password authentication, IPv6, domain names resolved by the proxy and UDP support. SOCKS4 handles only IPv4 TCP connections without real authentication.

Is a SOCKS5 proxy better than an HTTP proxy?

Not in general. SOCKS5 is more flexible because it carries any TCP traffic; HTTP proxies are more widely supported for web work. For HTTPS websites the result is similar.

Does a SOCKS5 proxy encrypt traffic?

No. It relays data as it is. Your traffic is encrypted only if the application uses encryption, such as HTTPS, or if you tunnel it through SSH.

What is socks5h?

A proxy URL scheme used by curl and Python requests that tells the client to let the SOCKS5 proxy resolve host names, instead of resolving them locally.

Does ProxyEmpire support SOCKS5?

Yes. HTTP and SOCKS5 work on the same host, port and credentials, for residential and mobile proxies. UDP is not supported.

What port does SOCKS use?

1080 is the traditional default, but providers can use any port. ProxyEmpire uses port 5000 for its gateway.

References

Primary documentation
  1. RFC 1928: SOCKS Protocol Version 5Handshake, CONNECT, BIND, UDP ASSOCIATE and reply codes
  2. RFC 1929: Username/Password Authentication for SOCKS V5Password authentication
  3. RFC 1961: GSS-API Authentication Method for SOCKS Version 5Kerberos-style authentication
  4. curl manualsocks5:// and socks5h:// proxy schemes
  5. OpenSSH ssh(1) manualThe -D dynamic port forwarding option

SOCKS5 and HTTP on the same endpoint

More than 30 million residential and 4 million mobile IPs over HTTP or SOCKS5 with the same credentials, targeting by country, city and ISP at no extra cost, and 24/7 support from real people. Try it for $1.97.

Flexible Pricing Plan

logo purple proxyempire

Our state-of-the-art proxies.

Experience online freedom with our unrivaled web proxy solutions. Pioneering in collecting location specific data at scale, our premium, ethically-sourced network boasts a vast pool of IPs, expansive location choices, high success rate, and versatile pricing. Advance your digital journey with us.

๐Ÿ˜๏ธ Rotating Residential Proxies
  • 30M+ Premium Residential IPs
  • ย 170+ Countries
    Every residential IP in our network corresponds to an actual desktop device with a precise geographical location. Our residential proxies aare fast and reliable, with 99.9% uptime, and work for a wide range of use cases. You can use Country, Region, City and ISP targeting for our rotating residential proxies.

See our Rotating Residential Proxies

๐Ÿ“ Static Residential Proxies
  • 19 Countries
    Buy a dedicated static residential IP from one of the 19 countries that we offer proxies in. Keep the same IP for a month or longer, while benefiting from their fast speed and stability.

See our Static Residential Proxies

๐Ÿ“ณ Rotating Mobile Proxies
  • 4M+ Premium Mobile IPs
  • ย 170+ Countries
    Access millions of clean mobile IPs with precise targeting including Country, Region, City, and Mobile Carrier. Get far fewer IP blocks and CAPTCHAs with our 4G and 5G proxies.

See our Mobile Proxies

๐Ÿ“ฑ Dedicated Mobile Proxies
  • 5+ Countries
  • 50+ Locations
    Get your own dedicated mobile proxy in one of our supported locations, with unlimited bandwidth and unlimited IP changes on demand. A great choice when you need a small number of mobile IPs and a lot of proxy bandwidth.

See our 4G & 5G Proxies

๐ŸŒ Rotating Datacenter Proxies
  • 197,000+ IPs Premium IPs
  • ย 62 Countries
    On a budget and need to do some simple scraping tasks? Our datacenter proxies are the perfect fit! Get started with as little as $2

See our Datacenter Proxies

proxy locations

30M+ rotating IPs

99% uptime - high speed

99.9% uptime.

dedicated support team

24/7 Dedicated Support.

fair price

Fair Pricing.

๐Ÿ  Residential Proxies Rotating / Static / Unlimited
๐Ÿ“ฑ Mobile Proxies Rotating and Dedicated
๐Ÿ–ฅ๏ธ Datacenter Proxies Rotating
๐ŸŒ IP Pool 30M+ residential + 4M+ mobile IPs
๐Ÿ“ถ Uptime 99.9% ยท Live status
๐Ÿ’ณ Payment Card ยท PayPal ยท Crypto ยท Bank transfer
๐Ÿ’ฌ Support 24/7 live chat ยท sales@proxyempire.io