macOS SOCKS5 Proxy Setup: System-Wide, Terminal, and Per-App Configuration
macOS does have a system SOCKS proxy setting, but apps do not all respect it. Here is how to set it in System Settings and networksetup, route Terminal and developer tools, and verify DNS and leaks.
macOS does have a SOCKS proxy setting, which makes it feel like a system-wide switch. In practice, Safari and some apps follow it, while Terminal, Homebrew, and many developer tools ignore it. This guide shows how to set a SOCKS5 proxy on macOS from System Settings and networksetup, then how to make the tools you actually use honor it without DNS leaks.
Where macOS Keeps Its SOCKS Proxy Setting
Open System Settings > Network. Select Wi-Fi or Ethernet, click Details, then Proxies. You will see checkboxes for Web Proxy (HTTP), Secure Web Proxy (HTTPS), SOCKS Proxy, and others. The SOCKS Proxy section asks for a server and port. It does not offer a protocol version dropdown. For strict control, configure individual apps with socks5h when they support it.
Set the macOS SOCKS Proxy from System Settings
- Open System Settings > Network.
- Select the active network service, such as Wi-Fi.
- Click Details > Proxies.
- Enable SOCKS Proxy.
- Enter the server address and port.
- Add any bypass domains you need, such as local resources.
- Click OK and apply.
Keep in mind that this setting affects apps that respect the macOS system proxy. It does not guarantee that every connection from every app goes through the proxy.
Set It from Terminal with networksetup
networksetup is useful for scripts, remote support, and quick changes.
# List network services
networksetup -listallnetworkservices
# Set SOCKS proxy for Wi-Fi
networksetup -setsocksfirewallproxy 'Wi-Fi' 127.0.0.1 1080
# Turn it on
networksetup -setsocksfirewallproxystate 'Wi-Fi' on
# Check the current setting
networksetup -getsocksfirewallproxy 'Wi-Fi'
# Turn it off
networksetup -setsocksfirewallproxystate 'Wi-Fi' off
You can also set bypass domains:
networksetup -setproxybypassdomains 'Wi-Fi' '*.local' '169.254/16' 'localhost'
Use quotes around the network service name, especially if it contains spaces.
Make Terminal and Developer Tools Use SOCKS5
Terminal sessions generally do not inherit the macOS SOCKS proxy setting. Set environment variables for the current shell:
export ALL_PROXY=socks5h://127.0.0.1:1080
export all_proxy=socks5h://127.0.0.1:1080
Some tools use HTTP_PROXY and HTTPS_PROXY. Be careful: not every tool understands a socks5h:// value in those variables. If a tool has a dedicated SOCKS flag, use that instead.
curl
curl --socks5-hostname 127.0.0.1:1080 https://api.ipify.org
git
git config --global http.proxy socks5h://127.0.0.1:1080
git config --global https.proxy socks5h://127.0.0.1:1080
# Remove later
git config --global --unset http.proxy
git config --global --unset https.proxy
Python
import requests
proxies = {
'http': 'socks5h://127.0.0.1:1080',
'https': 'socks5h://127.0.0.1:1080',
}
print(requests.get('https://api.ipify.org?format=json', proxies=proxies, timeout=10).json())
Browser Notes: Safari, Chrome, and Firefox
- Safari typically follows the macOS system proxy.
- Chrome on macOS generally uses system proxy settings unless launched with explicit proxy flags.
- Firefox has its own network settings. If it is set to Use system proxy settings, it should follow macOS. If you need remote DNS, set Firefox to Manual proxy configuration and enable Proxy DNS when using SOCKS v5.
After changing browser settings, test in a private window so cached connections do not mislead you.
Verify the Proxy and Spot DNS Leaks
Check the system proxy configuration:
scutil --proxy
Check the exit IP:
curl --socks5-hostname 127.0.0.1:1080 https://api.ipify.org
Then compare with a DNS leak test. The key distinction is socks5 versus socks5h: socks5 may resolve DNS locally, while socks5h sends the hostname to the proxy for resolution. If geo-targeting matters, remote DNS is usually what you want.
Turn It Off and Avoid Common Pitfalls
- Disable the proxy when you no longer need it; captive portals and local devices may fail otherwise.
- Check for conflicts with VPN clients and other network extensions.
- Remember that system proxy settings do not cover every app.
- If the proxy runs on another machine, do not use
127.0.0.1. - Verify the actual app you care about, not just Terminal.
Takeaway
macOS gives you a real system SOCKS proxy checkbox, but it is not a universal solution. Use System Settings or networksetup for apps that follow the system proxy, then configure Terminal and developer tools directly with socks5h and verify DNS behavior.