How to Use Proxies on Android (and Why Wi-Fi Proxy Settings Only Offer HTTP, Not SOCKS5)
Android's built-in Wi-Fi proxy dialog has no protocol option, because it is HTTP-only. Here is what that means for SOCKS5, why some apps ignore the setting, and the practical ways to get proxied traffic on Android.
Long-press your Wi-Fi network on Android, tap Modify network, expand Advanced options, set Proxy to Manual, and you get a hostname field, a port field, and a bypass list. That is it. No protocol dropdown, no SOCKS5 option, no authentication prompt.
If you have been searching for how to use proxies on Android and wondering why SOCKS5 never appears, this is the reason: Android's built-in Wi-Fi proxy setting is an HTTP proxy, not a general-purpose SOCKS5 client.
What Android's built-in proxy setting actually supports
- HTTP and HTTPS only. HTTPS traffic is tunnelled with an HTTP
CONNECTrequest, which is why HTTPS sites work even though the proxy itself is HTTP. - No SOCKS4, SOCKS5, or SOCKS5h. There is simply no field for it.
- No UDP. Anything UDP-based - QUIC, game traffic, DNS over the same path - will not go through it.
- Per-network. The setting is saved with the Wi-Fi network you edited, so it does not apply when you switch networks or use mobile data.
- Advisory, not enforced. Android hands the proxy configuration to apps, but apps are free to ignore it.
That last point surprises people most. A browser usually respects the system proxy; many other apps, especially those bundling their own HTTP client or networking library, connect directly and never touch the proxy at all. Mobile data has no equivalent user-facing proxy field on most devices, so there is nothing to configure there either.
Why SOCKS5 on Android is usually a dead end with built-in tools
Even when an app offers its own SOCKS5 field, three things tend to go wrong:
- Where DNS is resolved. SOCKS5 has a variant that resolves hostnames remotely, usually written as
socks5h. If the app resolves names locally first, your DNS queries go to your ISP while your traffic exits elsewhere - a partial leak. - UDP support. SOCKS5 does define a UDP association, but client support is inconsistent and Android's own stack does not expose it through the system proxy.
- Authentication. Username/password authentication is part of the SOCKS5 handshake, but whether an app surfaces those fields is up to the developer.
The practical ways to get proxied traffic on Android
Option 1: The built-in HTTP proxy (fastest, most limited)
- Open Settings, then Network & internet, then Internet (labelled Wi-Fi on older versions).
- Long-press your network and choose Modify network.
- Expand Advanced options and set Proxy to Manual.
- Enter the proxy hostname and port. Some versions also show a bypass list - add local addresses there.
- Save, then reconnect to the network.
Test it by visiting an IP-check page in your browser and comparing the result with the proxy switched off. If the browser shows the proxy IP but an app still shows your real one, that app is ignoring the system proxy.
Option 2: An app that builds a local VPN interface
Apps that create a local VPN tunnel can capture device traffic and forward it to a proxy endpoint, which sidesteps the HTTP-only limitation. Two things to understand before you go down this road:
- Android allows one active VPN at a time, so this competes with any VPN app you already use.
- The app is now in the traffic path for everything it captures. Choose it as carefully as you would choose a VPN provider.
Option 3: Terminate the proxy somewhere else
Instead of making Android speak SOCKS5, put the SOCKS5 client on a machine you control - a home server, a router, or a small cloud instance - and connect Android to that. Terminating SOCKS5 in an SSH dynamic-forward tunnel (ssh -D) on a desktop and sharing that connection is a common pattern.
Option 4: Root-level redirection
With root, kernel-level redirection can send all TCP traffic to a SOCKS5 proxy, bypassing per-app proxy support entirely. This carries a real risk of breaking connectivity and is not a casual option.
Test it properly from the command line
If you have a terminal app on the device, verify the proxy independently of the browser:
# Check the IP the proxy presents
curl -s --proxy socks5h://user:[email protected]:1080 https://api.ipify.org; echo
# Same proxy, JSON output for scripting
curl -s --proxy socks5h://user:[email protected]:1080 "https://api.ipify.org?format=json"
If those commands show the proxy's address but your browser does not, the problem is app-level configuration rather than the proxy itself.
Security notes worth taking seriously
- An HTTP proxy sees the destination of every request. HTTPS keeps the content encrypted, but the metadata is still visible to whoever runs the proxy.
- Free public proxies on any platform should be treated as hostile. Never send credentials or session cookies through one.
- If a proxy is transparent, free, and requires no account, ask what the business model is before you route anything sensitive through it.
Takeaway
Android's Wi-Fi proxy dialog is an HTTP-only convenience, not a SOCKS5 client - that is a platform limitation, not a misconfiguration on your end. Use the built-in setting for simple browser-level HTTP proxying, use a local VPN-tunnelling app when you need device-wide routing to a SOCKS5 endpoint, and consider terminating SOCKS5 elsewhere, such as an SSH tunnel or a router you control, if you want the flexibility without root. Whichever route you take, verify with an IP check from both the browser and the command line before trusting it.