How to Use a SOCKS5 Proxy on Windows 10 and 11: System, Browser, and App-Specific Setup
Windows Settings has a proxy box, but it is not a true SOCKS5 switch. Here is what actually routes Windows traffic through SOCKS5 — per-app settings, SSH dynamic forwarding, WSL, and wrappers — plus how to verify DNS and leaks.
Windows users searching for how to use a SOCKS5 proxy often start in Settings and get stuck. The manual proxy box looks like it should accept any proxy, but it does not offer a SOCKS5 protocol switch. This guide covers what actually works on Windows 10 and 11, from per-app settings to SSH tunnels and application wrappers, and how to verify that DNS and WebRTC are not leaking.
The Short Answer: Windows Has No Built-In System-Wide SOCKS5 Toggle
- Windows Settings includes a manual proxy setup, but it is designed around HTTP/HTTPS proxying.
netsh winhttp set proxyconfigures WinHTTP for some system components; it is not a general SOCKS5 switch.- Many Windows apps ignore the system proxy entirely unless they explicitly support it.
- For reliable SOCKS5, configure each app, use an app-specific proxifier, or create a local SOCKS5 proxy with SSH and point apps at it.
What the Windows 10 and 11 Proxy Settings Actually Do
In Settings, go to Network & Internet > Proxy > Manual proxy setup. You get Address and Port fields, plus a bypass list. There is no SOCKS4 or SOCKS5 dropdown. This setting is commonly used for HTTP proxies, and behavior varies by app. Chrome and Edge may follow system proxy settings, while Firefox has its own proxy configuration. Native Windows apps and command-line tools often need separate configuration.
Option 1: Configure SOCKS5 per App
For browsers, use Firefox if you want direct SOCKS5 control. In Firefox, open Settings, search for proxy, choose Manual proxy configuration, enter the SOCKS Host and Port, select SOCKS v5, and enable Proxy DNS when using SOCKS v5 if you want remote DNS resolution.
For command-line tools, use flags or environment variables that the tool supports.
curl
# Resolve DNS at the proxy (recommended for geo checks)
curl --socks5-hostname 127.0.0.1:1080 https://api.ipify.org
# Resolve DNS locally
curl --socks5 127.0.0.1:1080 https://api.ipify.org
--socks5-hostname is equivalent to using a socks5h:// proxy URL in many tools. The h means hostname resolution happens at the proxy side, which matters for geo-targeting and DNS leak checks.
git
git config --global http.proxy socks5h://127.0.0.1:1080
git config --global https.proxy socks5h://127.0.0.1:1080
# Remove later
git config --global --unset http.proxy
git config --global --unset https.proxy
Python with requests
python -m pip install 'requests[socks]'
import requests
proxies = {
'http': 'socks5h://127.0.0.1:1080',
'https': 'socks5h://127.0.0.1:1080',
}
response = requests.get('https://api.ipify.org?format=json', proxies=proxies, timeout=10)
print(response.json())
Option 2: Create a Local SOCKS5 Proxy with SSH
If you have an SSH server you trust, dynamic forwarding turns it into a local SOCKS5 proxy.
ssh -D 1080 -N -C [email protected]
Keep that terminal open while you work. Then point apps at 127.0.0.1:1080. This is useful when you only need a proxy for a browser, a script, or a specific tool. It does not automatically reroute every Windows application.
Option 3: Route Specific Apps with Proxifier-Style Tools
Some applications have no proxy settings at all. Proxifier-style tools can intercept connections from selected Windows programs and send them through a SOCKS5 proxy. When evaluating one, check:
- Whether it supports SOCKS5 with remote DNS.
- How it handles DNS for proxied and non-proxied apps.
- Whether rules are based on app name, target host, port, or a mix.
- How it behaves when the proxy fails.
- Whether it logs sensitive connection data.
Option 4: WSL, Windows Terminal, and Linux Tools
WSL2 runs in a separate virtual network. If the SOCKS5 proxy runs on Windows, 127.0.0.1 inside WSL may not reach it. In that case, use the Windows host IP or the address WSL uses to reach the host, then set environment variables:
export ALL_PROXY=socks5h://WINDOWS_HOST_IP:1080
export all_proxy=socks5h://WINDOWS_HOST_IP:1080
Not every Linux tool honors ALL_PROXY. For tools that support a SOCKS5 flag, use the flag directly.
How to Verify the Proxy and Check DNS Leaks
- Check your public IP with the proxy enabled and disabled.
- Confirm the country and ASN match your expectation.
- Run a DNS leak test. If DNS resolves locally when you expected remote resolution, use
socks5hor enable remote DNS in the app. - Test in the actual browser or app you care about, not only with
curl. - Check WebRTC behavior in browsers if you need to hide public IP addresses from page scripts.
Common Windows SOCKS5 Mistakes
- Expecting the Windows Settings proxy box to provide system-wide SOCKS5.
- Mixing
socks5://andsocks5h://and getting different DNS behavior. - Forgetting that each app has its own proxy support.
- Using free SOCKS5 proxies for logins, payments, or sensitive data.
- Leaving a proxy enabled after testing and breaking local services.
Takeaway
Windows does not offer a single SOCKS5 switch. The practical path is to choose where the proxy should apply: one app, a browser, a command-line session, or a wrapped set of applications. Configure that layer directly, use socks5h when remote DNS matters, and verify the result instead of assuming it works.