Skip to content

SOCKS5 Configurator Guide: Browsers, SSH, curl, git, and Python

A practical SOCKS5 configuration walkthrough for Firefox, macOS, Linux, SSH dynamic forwarding, curl, git, and Python — including the socks5 versus socks5h distinction that causes most geo and DNS leaks.

Searching for a SOCKS5 configurator usually means you already have a host, a port, and possibly a username and password — and you want a browser, a shell, or a script to route traffic through it. There is no single universal configurator, but every place you configure SOCKS5 needs the same few values, and the quirks are predictable. This guide covers the setups people actually use.

What SOCKS5 Is, in About 60 Seconds

SOCKS5 (RFC 1928) is a transport-layer proxy protocol. Your client opens a connection to the proxy, asks it to reach a destination, and then relays bytes in both directions. Two consequences follow from that design:

  • The proxy does not parse or rewrite application protocols, so it carries HTTPS, SSH, and arbitrary TCP traffic without special configuration.
  • SOCKS5 does not encrypt anything. Confidentiality comes from the destination protocol (HTTPS, SSH) or from running the tunnel over an encrypted transport such as SSH.

Username and password authentication for SOCKS5 is a separate specification, RFC 1929. Client support for it varies, and that variation causes a large share of configuration problems.

The Values You Need Before You Start

  1. Host — the proxy hostname or IP address.
  2. Port — the listening port supplied by the provider or tunnel.
  3. Authentication — a username and password, IP allowlisting, or none.
  4. Scheme — whether your tool expects socks5:// or socks5h://.

socks5:// vs socks5h:// and Why DNS Decides Your Geo

Scheme Who resolves DNS Encrypts traffic Use when
socks5:// your machine no local DNS resolution is acceptable
socks5h:// the proxy no you want lookups and geo to match the proxy
http:// prefix your machine no you are using an HTTP proxy, not SOCKS
https:// prefix your machine TLS to the proxy the provider offers a TLS-wrapped proxy endpoint

The h means the hostname is resolved by the proxy. Using socks5:// when you wanted socks5h:// is the most common cause of a proxy that works but still shows the wrong region, and it can also expose the hostnames you visit to your local resolver. Only some tools — curl, git via libcurl, and certain Python libraries — honour the socks5h convention; GUI applications usually expose it as a checkbox instead.

Configuring SOCKS5 in Firefox

Firefox is the easiest mainstream browser to point at a SOCKS5 proxy because it keeps its own proxy settings instead of inheriting the operating system's.

  1. Open Settings and search for Network Settings, or navigate to Settings, then General, then Network Settings.
  2. Choose Manual proxy configuration.
  3. Enter the host and port in the SOCKS Host field and select SOCKS v5.
  4. Tick Proxy DNS when using SOCKS v5 if the proxy should resolve hostnames.
  5. Leave the HTTP proxy fields empty unless you also have an HTTP proxy.
  6. Click OK, then load a page that reports your IP address to confirm the change.

Chrome, Edge, and Other Chromium Browsers

Chromium-based browsers read the operating system proxy settings. For isolated testing, launch one with a flag and a throwaway profile:

# macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \
  --proxy-server="socks5://127.0.0.1:1080" \
  --user-data-dir=/tmp/chrome-socks-test
# Linux
google-chrome --proxy-server="socks5://127.0.0.1:1080" --user-data-dir=/tmp/chrome-socks-test

Two caveats. The separate --user-data-dir keeps the test isolated from your normal profile, and the flag is not a reliable place for credentials — if your proxy requires authentication, configure it in the operating system settings or route through a local forwarder instead of embedding a username and password in the flag.

macOS: Configure SOCKS5 From the Terminal

The networksetup utility writes exactly the same setting the Network preferences pane exposes.

# List available network services if you are unsure of the name
networksetup -listallnetworkservices

# Replace "Wi-Fi" with your active service name
sudo networksetup -setsocksfirewallproxy "Wi-Fi" 127.0.0.1 1080
sudo networksetup -setsocksfirewallproxystate "Wi-Fi" on

# Turn it back off
sudo networksetup -setsocksfirewallproxystate "Wi-Fi" off

Many command-line tools ignore macOS system proxy settings entirely and need their own configuration, so do not assume the terminal is covered once this command succeeds.

Linux and CLI Tools: Environment Variables

export ALL_PROXY="socks5h://user:[email protected]:1080"
export all_proxy="$ALL_PROXY"

A large number of command-line tools read ALL_PROXY or its lowercase variant. Check what is currently set with env | grep -i proxy. Graphical applications on Linux generally follow the desktop environment's proxy settings rather than these variables, so configure both paths or use a wrapper such as proxychains for stubborn binaries.

SSH: Turn a Server You Control Into a SOCKS5 Proxy

# -D enables dynamic (SOCKS) forwarding, -N runs no remote command, -C compresses
ssh -N -C -D 1080 [email protected]

# Add -f to push it into the background
ssh -f -N -C -D 1080 [email protected]

This is often the fastest way to get a working SOCKS5 endpoint. Nothing needs to be installed on the remote server, no elevated privileges are required, and the hop between your machine and the server is encrypted by SSH — which addresses one of SOCKS5's weaknesses. Point your browser or CLI at 127.0.0.1:1080 once the tunnel is up.

curl, git, and Python

# Resolve DNS locally
curl --socks5 127.0.0.1:1080 https://api.ipify.org

# Resolve DNS at the proxy
curl --socks5-hostname 127.0.0.1:1080 https://api.ipify.org

# With username and password authentication
curl --socks5-hostname 127.0.0.1:1080 \
  --proxy-user "USER:PASS" \
  https://api.ipify.org
# Route git through a SOCKS5 proxy; git uses libcurl underneath
git config --global http.proxy  socks5h://127.0.0.1:1080
git config --global https.proxy socks5h://127.0.0.1:1080

# Undo when you are finished
git config --global --unset http.proxy
git config --global --unset https.proxy
# Requires: pip install "requests[socks]"
import requests

proxies = {
    "http": "socks5h://user:[email protected]:1080",
    "https": "socks5h://user:[email protected]:1080",
}

response = requests.get("https://api.ipify.org", proxies=proxies, timeout=15)
print(response.status_code, response.text)

The requests library needs the PySocks dependency before it understands SOCKS proxies. Without it, you get a missing-dependencies error raised before any connection is attempted, which is easy to misread as a proxy failure.

Troubleshooting the Failures You Will Actually Hit

Symptom Likely cause Fix
Connection refused Nothing is listening on that port Confirm the port and that the proxy or SSH tunnel is running
SOCKS5 authentication failed Wrong credentials, or the proxy expects an allowlisted IP Re-check the credentials; drop them if you are allowlisted
The site still shows the wrong region DNS resolved locally because you used socks5:// Switch to socks5h:// or enable remote DNS
407 Proxy Authentication Required You are pointed at an HTTP proxy port, not SOCKS Check the provider's port list
Works in curl, fails in the browser Browser uses system settings, or an extension overrides them Disable proxy extensions and verify system settings
UDP applications fail SOCKS5 UDP association is rarely implemented client-side Use a VPN for UDP traffic instead

Verify Before You Trust It

# Compare the reported IP with and without the proxy
curl -sS https://api.ipify.org; echo
curl -sS --socks5-hostname 127.0.0.1:1080 https://api.ipify.org; echo

If both addresses are identical, traffic is not going through the proxy. When geo accuracy matters, also run a DNS leak test in the browser to confirm lookups are leaving through the proxy rather than your local resolver.

Takeaway

A SOCKS5 configurator is really just four values applied in the right place: host, port, credentials, and a decision about where DNS gets resolved. Configure the browser or CLI tool you actually use, confirm the exit IP with the curl comparison above, and default to socks5h:// whenever geo accuracy or DNS privacy matters.