SOCKS5 proxies
A transport-level proxy that moves bytes through a tunnel rather than parsing HTTP requests — the same credential, reached with a different scheme on its own port.
Pick this when
Your client speaks SOCKS rather than HTTP proxying.
- Layer
- A TCP tunnel — bytes are forwarded, not parsed
- Carries
- TCP to ports 80, 443 and 8080 — the same three as the HTTP endpoint
- Does not carry
- UDP. The route to the network is a TCP tunnel end to end
- Your headers
- Not read and not rewritten in transit
How it works
An HTTP proxy parses your request and forwards it. SOCKS5 does not: it opens a tunnel and moves bytes. That changes how your client connects, not what it can reach — both schemes are held to the same four destination ports.
It also means SOCKS5 does not read or modify your traffic. There are no headers rewritten in transit and nothing inspecting the payload.
It is the same credentials as the HTTP endpoint, with the same targeting in the username. What changes is the scheme your client is given and the port it dials: HTTP and SOCKS5 listen separately, and the wrong one does not refuse you — it hangs. Take both from the dashboard or from the API rather than editing a line by hand.
How it differs
Against its nearest neighbours, by name. If one of these describes your situation better, the row is a link.
Where it fits
Use it for
- Non-HTTP protocols that already run on an allowed web port — usually 443
- Tools that expect a SOCKS endpoint rather than an HTTP proxy
- Cases where you want the proxy to move bytes without touching headers
- Clients that are already pointed at a SOCKS endpoint and would rather not be reconfigured
Do not use it for
- SSH, mail, databases and anything else off a web port — the network answers 424 to a CONNECT for anything but 80, 443 and 8080, measured; 8443 is refused too, despite looking like it belongs
- Plain web scraping where an HTTP proxy is simpler to configure and equally effective
- Clients with no SOCKS support, where you would be adding a wrapper for no benefit
- UDP traffic — every route we offer is a TCP tunnel, whichever protocol you speak to it
If your client speaks HTTP and your target is a website, use the HTTP endpoint. Reach for SOCKS5 when your client demands it, not by default.
A real connection
One credential pair covers everything. Type, country, rotation and session all travel inside the username, so you never provision a second proxy user to change one of them.
socks5://user-Ex4mpleUser12345-type-residential-country-FR:YOUR-SECRET@geo.g-w.info:10800A standard proxy URL, so most clients accept it directly with no adapter. Same credential and same targeting as the HTTP example — the scheme AND the port differ, because the two protocols listen separately.
Questions
- What can SOCKS5 do that an HTTP proxy cannot?
- Less than the usual answer suggests. SOCKS5 forwards bytes without reading them, so a client that cannot be pointed at an HTTP proxy can still use us — but it reaches no further. Both schemes reach ports 80, 443 and 8080 only, so SSH, mail and database ports are refused whichever you pick — and so is 8443, which surprises people.
- Is SOCKS5 more private?
- It touches your traffic less — no headers are rewritten in transit. That is not the same as encryption: use HTTPS inside the tunnel if the payload needs protecting.
- Does SOCKS5 cost more?
- No. Protocol choice does not change the rate. You are billed by the gigabyte regardless of how the bytes are carried.
- Can I use SOCKS5 with any proxy type?
- Yes — residential, datacenter and mobile all accept SOCKS5, on the same credential and the SOCKS5 port. The IP class is a username parameter; the protocol is how your client is configured, and each protocol has its own port.
The same on every type
These four do not vary by proxy type, so they are worth stating once rather than six times. One balance covers all of it.
- Protocols
- HTTP and SOCKS5, one port each. Destinations on 80, 443 and 8080
- Targeting
- Country always; then a state or a city, in unaccented letters, digits and underscores; ASN by number
- Rotation
- Per request (-1), sticky (0), or 5 / 10 / 15 / 20 / 60 minutes
- Rate
- $3/GB, sent plus received
Where the address comes from
Pick exactly one.
- IP classThe target rejects hosting ranges but does not need a carrier address.
Residential proxies
- IP classNothing is blocking you yet, or a predictable round trip matters more than provenance.
Datacenter proxies
- IP classResidential was rejected too, or the platform expects a carrier address.
Mobile proxies