Skip to content
Article / 6 min read

How to Use a SOCKS5 Proxy in Chrome: Extensions, System Settings, and SSH Tunnels

Chrome has no built-in SOCKS5 setting. Here are the practical ways to route Chrome through a SOCKS5 proxy — system settings, command-line flags, extensions, and SSH tunnels — plus how to verify it and avoid DNS and WebRTC leaks.

If you have ever opened Chrome's settings and searched for a SOCKS5 proxy option, you already know the result: it does not exist. Unlike Firefox, which has a dedicated SOCKS5 host field in its connection settings, Chrome deliberately omits a per-browser proxy configuration UI. That does not mean you cannot use SOCKS5 with Chrome — it just means you have to choose one of several indirect routes. This guide covers each practical method, the trade-offs, and the leak checks that actually matter.

Why Chrome Has No Native SOCKS5 Setting

Chrome delegates proxy configuration to the operating system on Windows and macOS. On Linux, it respects environment variables and command-line flags. The reasoning is simple: a browser-level proxy setting would conflict with corporate system policies and other applications. But the side effect is that SOCKS5, which is not supported by the Windows system proxy dialog, becomes awkward on that platform.

Chrome does understand SOCKS5 when you tell it to via a command-line flag or a proxy extension. The important distinction is what Chrome resolves: when you point Chrome at a socks5:// proxy, it sends the hostname to the proxy for remote DNS resolution (equivalent to the socks5h scheme in tools like curl). That is what you want for geo-unblocking and DNS-leak prevention.

Method 1: System-Wide SOCKS5 Proxy (macOS and Linux Only)

On macOS and Linux, you can set a system-wide SOCKS5 proxy and Chrome will follow it. On Windows, this method does not work because the Windows proxy settings only accept HTTP and HTTPS.

macOS

  1. Open System Settings (or System Preferences on older macOS).
  2. Go to Network → select your active connection → Details → Proxies.
  3. Enable SOCKS Proxy and enter the host and port (e.g., 127.0.0.1:1080).
  4. Click OK and Apply.

Chrome will now route all traffic through the SOCKS5 proxy. Note that this affects every application that respects system proxy settings, not just Chrome.

Linux

Chrome on Linux reads the all_proxy environment variable. Set it before launching Chrome:

export all_proxy="socks5://127.0.0.1:1080"
google-chrome

If that does not work for all traffic, you can use the --proxy-server flag instead (see Method 2).

Method 2: Chrome Command-Line Flags (All Platforms)

The most reliable way to force Chrome through a SOCKS5 proxy, regardless of OS, is to launch it with a proxy server flag. Close all Chrome instances first, then run:

# macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --proxy-server="socks5://127.0.0.1:1080"

# Linux
google-chrome --proxy-server="socks5://127.0.0.1:1080"

# Windows (Command Prompt)
"C:\Program Files\Google\Chrome\Application\chrome.exe" --proxy-server="socks5://127.0.0.1:1080"

This flag makes Chrome use the SOCKS5 proxy for all requests and performs remote DNS resolution. To confirm, visit chrome://net-internals/#proxy and look for the effective proxy settings.

One caveat: this only applies to the Chrome instance launched with the flag. If you open a new window from an existing Chrome process, it may not inherit the setting. Use a separate user-data-dir if you need isolation.

Method 3: Proxy Extensions for SOCKS5

Browser extensions are the most common way to add SOCKS5 to Chrome without touching system settings. Extensions such as SwitchyOmega (and similar proxy managers) let you define a SOCKS5 profile and switch between direct and proxied connections per tab or per domain.

How to set up a typical extension:

  1. Install the extension from the Chrome Web Store.
  2. Create a new profile, choose SOCKS5 as the protocol.
  3. Enter the proxy host and port (e.g., 127.0.0.1:1080).
  4. Leave authentication blank if your proxy does not require it.
  5. Apply the profile.

Extensions only affect Chrome traffic, and they can be convenient for testing. However, they do not prevent WebRTC leaks and may not cover Chrome's internal DNS lookups in all cases. Always verify with a leak test.

Method 4: SSH Dynamic Port Forwarding (Local SOCKS5 Tunnel)

If you have SSH access to a remote server, you can create a local SOCKS5 proxy with a single command:

ssh -D 1080 -N -f [email protected]

This opens a SOCKS5 proxy on localhost:1080 that tunnels traffic through your server. Then point Chrome at it using either the command-line flag or a proxy extension. This method is popular because it encrypts traffic between you and the server and requires no third-party proxy service.

To close the tunnel, find the SSH process and kill it, or use ssh -D 1080 -N [email protected] in a terminal and press Ctrl+C when done.

Verifying Your SOCKS5 Proxy Works (and Is Not Leaking)

After configuring any method, check the following:

  • Public IP: Visit an IP-checking website and confirm it shows the proxy's IP, not your real one.
  • DNS leaks: Use a DNS leak test site. Because Chrome's socks5:// does remote DNS, you should see DNS servers belonging to the proxy, not your ISP.
  • WebRTC leaks: Chrome can expose your local and public IP through WebRTC even when a proxy is active. Test with a WebRTC leak test. To mitigate, disable WebRTC entirely or use an extension that blocks it.
  • Chrome's internal view: Go to chrome://net-internals/#proxy to see the current proxy configuration, and chrome://net-internals/#dns to see DNS resolution behavior.

Common Pitfalls: SOCKS5h, Authentication, and Chrome Policies

  • SOCKS5 vs SOCKS5h: In Chrome, socks5:// already performs remote DNS. There is no separate socks5h scheme. If you are used to curl's socks5h://, just use socks5:// in Chrome.
  • Authentication: Chrome supports SOCKS5 username/password authentication via the --proxy-server flag using the format socks5://user:pass@host:port. Some extensions also support it.
  • Enterprise policies: If your Chrome is managed by an organization, proxy settings may be enforced via policy. Check chrome://policy to see if a proxy configuration is locked.

Key Takeaway

Chrome will not give you a SOCKS5 checkbox, but you have four solid paths: system settings on macOS/Linux, command-line flags on any OS, a proxy extension, or an SSH tunnel. For most users, a proxy extension is the quickest way to test a SOCKS5 proxy in Chrome, while the command-line flag is the most reliable for persistent use. Whichever you choose, always verify your IP, DNS, and WebRTC status — a proxy that leaks is worse than no proxy at all.