iOS Proxy Settings: Why iPhone and iPad Wi-Fi Proxy Is HTTP-Only and How to Use SOCKS5
iOS Wi-Fi proxy settings have no SOCKS5 option, just a server and port. Here is what that HTTP proxy can and cannot do, how SOCKS5-capable apps work on iOS, and how to verify you are not leaking.
iOS proxy settings look simple: a server, a port, and a password. What they do not offer is a SOCKS5 option. That surprises users who want to route iPhone or iPad traffic through a SOCKS5 proxy. This guide explains what the built-in Wi-Fi proxy can do, why SOCKS5 needs a different approach on iOS, and how to verify that your traffic is actually proxied.
What the iOS Wi-Fi Proxy Setting Actually Supports
On iPhone or iPad, go to Settings > Wi-Fi, tap the information button next to the connected network, then Configure Proxy. You can choose Off, Manual, or Automatic. Manual asks for:
- Server
- Port
- Authentication, if required
There is no protocol dropdown for HTTP, HTTPS, SOCKS4, or SOCKS5. The built-in setting is an HTTP proxy. It can handle HTTP requests and typically HTTPS traffic through the HTTP CONNECT method, but it is not a SOCKS5 proxy.
What You Can Do with the Built-In HTTP Proxy
The built-in proxy is useful when you have an HTTP proxy that supports HTTPS tunneling. It can work for browsers and apps that respect the iOS system proxy. However:
- It does not accept SOCKS5 credentials or SOCKS5-specific options.
- It may not cover every app. Some apps use their own networking stack and ignore system proxy settings.
- It has limited bypass controls compared with desktop operating systems.
- It is not a replacement for a VPN or a SOCKS5-capable app when you need remote DNS and broader traffic routing.
Why SOCKS5 Needs a Different Approach on iOS
iOS apps are sandboxed. A normal app cannot easily create a local SOCKS5 listener that every other app can use. To route system-wide traffic through SOCKS5, you generally need an app that creates a Network Extension or Personal VPN profile. These apps can accept a SOCKS5 server and route traffic according to rules.
Common examples include Shadowrocket, Quantumult, and Potatso, but features, availability, and App Store presence vary by region and change over time. Check the current app listing and documentation before relying on one. This guide does not endorse a specific paid app or claim that any app is right for every use case.
Setting Up a SOCKS5 Proxy in a VPN-Profile App
The exact steps depend on the app, but the general flow is similar:
- Install a reputable app that explicitly supports SOCKS5.
- Add a new proxy or server configuration.
- Enter the host, port, and authentication details.
- Choose SOCKS5 as the protocol if the app asks.
- Decide between global routing and rule-based routing.
- Allow the VPN configuration when iOS prompts you.
- Enable the profile and test.
Remember that the app can see connection metadata. Use a trusted provider, keep the app updated, and avoid sending sensitive data through a proxy you do not control.
Can You Use SSH Dynamic Forwarding on iPhone?
SSH clients on iOS can create local port forwards, but those ports are usually only usable inside the same app. Because of sandboxing, you generally cannot point Safari or another app at 127.0.0.1:1080 from a separate SSH app. Some proxy apps integrate SSH tunnels directly; if you need that, check the app's documentation rather than assuming it works.
How to Verify the Proxy on iPhone and iPad
- Open Safari and check your public IP with the proxy enabled.
- Turn off Wi-Fi and check the IP again over mobile data.
- Run a DNS leak test to see whether DNS queries are resolving where you expect.
- Test the specific apps you care about, not just Safari.
- Check whether WebRTC or other browser features reveal an IP address that bypasses the proxy.
- Disable the proxy or VPN profile and confirm that traffic returns to normal.
Common iOS Proxy Mistakes
- Expecting the Wi-Fi proxy dialog to accept SOCKS5.
- Using an HTTP proxy for an app that only supports SOCKS5.
- Forgetting to disable the proxy after testing.
- Trying to use a local port from one app in another app.
- Trusting a free proxy app with login credentials.
- Assuming all apps follow the system proxy or VPN profile.
Takeaway
iOS built-in proxy settings are HTTP-only. For SOCKS5 on iPhone or iPad, use an app that creates a Network Extension or VPN profile and supports SOCKS5, then verify the exit IP and DNS behavior. If you only need HTTP proxying for a browser, the built-in setting may be enough; if you need SOCKS5 across apps, expect to use a dedicated tool.