HTTP vs SOCKS5: proxy protocol differences and which to use
Published · 3 min read
When you set up a proxy you're almost always asked for the type: HTTP or SOCKS5. Both work with nearly everything, but they're not the same. Here's what changes and how to choose in seconds.
How an HTTP proxy works
An HTTP proxy speaks the language of the web. Your software asks it for a page and the proxy fetches it on your behalf. For HTTPS sites — nearly all of them — the software uses the CONNECT method: it asks the proxy to open a tunnel to the site, then sends the encrypted connection through it. From then on the proxy only forwards bytes it can't read.
It's the most compatible type: browsers, operating systems, scripting libraries and almost every program with a "proxy" setting support it.
How a SOCKS5 proxy works
SOCKS5 works at a lower level: it doesn't know what a web page is, it forwards TCP connections to any address and port. That makes it suitable for non-web traffic too, such as mail clients, apps or custom protocols. The protocol also covers UDP traffic, but support depends on the provider and the software.
One important detail is DNS. With SOCKS5 the site's name can be resolved by the proxy rather than your computer, so DNS lookups also leave through the mobile network and not your own connection. In cURL and Python you get this with the socks5h:// scheme (the “h” stands for hostname).
Comparison
| HTTP | SOCKS5 | |
|---|---|---|
| Layer | Application (web) | Session (any TCP) |
| HTTPS sites | Yes, via CONNECT tunnel | Yes |
| Non-web traffic | No | Yes |
| DNS resolution | By the proxy for tunnelled requests | By the proxy with socks5h, otherwise local |
| Compatibility | Maximum | Very high |
| Authentication | Username and password | Username and password |
Security: what the proxy sees
With an HTTPS site, page content, passwords and cookies are encrypted from your software all the way to the site, with both HTTP and SOCKS5. The proxy only sees which site you connect to and how much traffic passes.
With a plain-HTTP site (increasingly rare) an HTTP proxy could read and modify the content. That's true of any network you pass through, not just proxies: always prefer HTTPS.
Which to choose
- Antidetect browsers (AdsPower, Multilogin, GoLogin, Dolphin{anty}): SOCKS5, so DNS goes through the proxy too. Both work as long as the type matches the one set on the proxy.
- Regular browser: HTTP is the simplest to configure; Firefox also handles SOCKS5 with remote DNS well (see the Firefox guide).
- Scripts (cURL, Python, Node.js): either; with SOCKS5 use
socks5h://. - Apps and non-web traffic: SOCKS5.
Practical examples
# HTTP
curl -x http://USER:PASSWORD@HOST:PORT https://api.ipify.org
# SOCKS5 with DNS via the proxy
curl -x socks5h://USER:PASSWORD@HOST:PORT https://api.ipify.orgimport requests # for SOCKS5: pip install "requests[socks]"
proxy = "socks5h://USER:PASSWORD@HOST:PORT"
r = requests.get("https://api.ipify.org", proxies={"http": proxy, "https": proxy}, timeout=30)
print(r.text)More complete examples are in the cURL, Python and Node.js guides.
Frequently asked questions
Is SOCKS5 faster than HTTP?
The difference is minimal: for HTTPS sites both forward an encrypted tunnel. Speed depends mostly on the proxy's network.
What is SOCKS4?
An old version of the protocol, without password authentication or IPv6. Today SOCKS5 is used.
Why does the connection fail with “proxy error”?
Most often the type selected in your software doesn't match the proxy's, or there's a typo in the username or password. Check the details in the proxy's Connection section.
Try a 5G mobile proxy
Dedicated smartphone, unlimited traffic, real carrier IPs. Live in minutes.
See plans