Build a Local SOCKS5 Configurator to Chain and Rotate ChangeMyIP Proxies (Windows, macOS, Linux)
Turn any app into a proxied app: run a local SOCKS5 configurator with gost, chain two ChangeMyIP endpoints for country-to-country routing, and rotate across residential nodes.
Overview
A SOCKS5 configurator is a small local service that listens on a port on your machine and forwards whatever your apps send through it to an upstream proxy, or through a chain of proxies. It is the practical answer when an application has no proxy settings of its own, or when you want several unrelated apps to share one proxy configuration instead of editing each one separately.
In this tutorial you will build that configurator with gost, an open-source proxy tool, and point it at ChangeMyIP SOCKS5 endpoints. You will then add a second hop for country-to-country chaining, rotate across multiple endpoints inside a hop, keep credentials out of sight, and run the listener persistently on Windows, macOS, and Linux.
Any SOCKS5 provider works with the configuration below. ChangeMyIP is used as the example because it offers SOCKS5 on dedicated and shared datacenter endpoints as well as rotating residential endpoints, and because flat monthly billing means an always-on local listener adds no per-request cost.
Prerequisites
- A ChangeMyIP plan that includes SOCKS5 access, plus your endpoint host, port, username, and password from the dashboard.
- One endpoint for every hop you plan to chain (chaining needs two independent endpoints).
- Permission to bind a listener on
127.0.0.1:1080, or any free local port. curlfor verification.- Basic comfort editing a YAML file.
How the Configurator Sits Between Your Apps and ChangeMyIP
Traffic path:
- An app opens a SOCKS5 connection to
127.0.0.1:1080. - The configurator accepts it and forwards the session to the first ChangeMyIP endpoint (the entry hop).
- If a second hop is defined, the entry endpoint opens a connection to the exit endpoint.
- The exit endpoint makes the outbound request and the response travels back down the chain.
What this buys you:
- A single local port that any app can use, including apps with no built-in proxy settings.
- Remote DNS resolution, so name lookups do not leak to your local resolver when you use the
socks5hscheme. - Deterministic egress: a datacenter endpoint for a stable IP, or a rotating residential endpoint when you need IP diversity.
- Chain routing: force traffic through a specific pair of locations by chaining two endpoints.
Steps
- Classify the ChangeMyIP endpoints you will use. Copy host, port, username, and password for each one, and note whether it is a dedicated datacenter endpoint, a shared datacenter endpoint, or a rotating residential endpoint.
| Role in the configurator | Endpoint type | When to use it |
|---|---|---|
| Entry hop | Dedicated datacenter | Fast, stable first leg; keep it close to your own region to limit latency |
| Entry hop | Residential rotating | When the first leg should not point back to one datacenter subnet |
| Exit hop | Datacenter or residential in the target country | When the final IP must appear in a specific country or city |
| Single hop (no chain) | Either | Everyday routing where one exit IP is enough |
- Install gost. Download the release archive for your operating system and architecture from the official gost releases page, then extract it.
Windows (PowerShell):
Expand-Archive -Path .\gost_*_windows_amd64.zip -DestinationPath .\gost
.\gost\gost.exe -V
macOS and Linux (use the darwin or linux archive and the matching amd64 or arm64 build):
tar -xzf gost_*_linux_amd64.tar.gz
sudo install -m 0755 gost /usr/local/bin/gost
gost -V
- Create the configurator configuration for a single hop. Save it as
gost.yamland restrict it, because it contains credentials.
chmod 600 gost.yaml
services:
- name: socks-in
addr: "127.0.0.1:1080"
handler:
type: socks5
chain: cmi-single
listener:
type: tcp
chains:
- name: cmi-single
hops:
- name: hop-exit
nodes:
- name: exit-dc
addr: proxy-host.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
Replace proxy-host.example:1080 with the endpoint from your ChangeMyIP dashboard and fill in the credentials issued with your plan.
- Start the listener and smoke-test it.
gost -C gost.yaml
In a second terminal, confirm the exit IP belongs to the proxy and not to you:
curl --silent --show-error --proxy socks5h://127.0.0.1:1080 https://api.ipify.org
echo
curl --silent https://api.ipify.org
echo
The first request should report the ChangeMyIP endpoint address; the second reports your own connection.
- Add a second hop to chain two locations. The request travels app, then entry endpoint, then exit endpoint, then the target site. The site sees the exit endpoint address; the exit endpoint sees the entry endpoint as its client.
services:
- name: socks-in
addr: "127.0.0.1:1080"
handler:
type: socks5
chain: cmi-two-hop
listener:
type: tcp
chains:
- name: cmi-two-hop
hops:
- name: hop-entry
nodes:
- name: entry-de
addr: entry-host.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
- name: hop-exit
nodes:
- name: exit-us
addr: exit-host.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
- Rotate across endpoints inside a hop with a selector. This is how you spread traffic over several distinct addresses instead of pinning one node.
- name: hop-exit
selector:
strategy: round
maxFails: 1
failTimeout: 30s
nodes:
- name: exit-us-1
addr: exit-us-1.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
- name: exit-us-2
addr: exit-us-2.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
- name: exit-us-3
addr: exit-us-3.example:1080
connector:
type: socks5
auth:
username: YOUR_USERNAME
password: YOUR_PASSWORD
If you would rather not list addresses yourself, point the hop at a single rotating residential endpoint: ChangeMyIP rotates the IP on its side, and the configurator only needs one node. The pool covers 40+ countries, 300+ cities, and 1000+ subnets, so you can spread rotation across many distinct networks when a task depends on looking like unrelated visitors.
- Point your applications at the local listener. Browser proxy settings take a SOCKS5 host of
127.0.0.1and port1080, with remote DNS enabled so names are resolved by the proxy. Command-line tools usually accept a flag or an environment variable:
export ALL_PROXY=socks5h://127.0.0.1:1080
export HTTPS_PROXY=socks5h://127.0.0.1:1080
Some tools ignore these variables and need an explicit flag, for example curl --proxy socks5h://127.0.0.1:1080. Always prefer the socks5h scheme over socks5 for anything privacy-sensitive.
- Keep the configurator running. On Linux, a systemd unit is the cleanest option:
[Unit]
Description=Local SOCKS5 configurator (gost)
After=network-online.target
Wants=network-online.target
[Service]
ExecStart=/usr/local/bin/gost -C /etc/gost/gost.yaml
Restart=on-failure
User=proxyuser
NoNewPrivileges=true
[Install]
WantedBy=multi-user.target
sudo install -m 0600 gost.yaml /etc/gost/gost.yaml
sudo systemctl daemon-reload
sudo systemctl enable --now gost
systemctl status gost
On Windows, create a Task Scheduler task that runs gost.exe -C C:\gost\gost.yaml at logon and set it to run whether or not the user is signed in. On macOS, run the same command from a terminal while testing, then wrap it in a LaunchAgent so it starts at login.
Verifying the Chain and DNS Behaviour
Repeat a request in a loop to see whether rotation is actually happening:
for i in 1 2 3; do
curl --silent --proxy socks5h://127.0.0.1:1080 https://api.ipify.org
echo
done
Check the reported location of the exit address:
curl --silent --proxy socks5h://127.0.0.1:1080 https://ifconfig.co/json
- A single hop returns the address of that endpoint. A two-hop chain returns the exit endpoint address, never the entry one. If you see the entry address, the chain is not being applied.
- The
socks5hscheme asks the proxy to resolve hostnames. Plainsocks5://resolves locally, which can leak your resolver and your approximate location even though the traffic itself is proxied. - If every request returns the same address with a selector configured, check that
maxFailsandfailTimeoutare not excluding nodes, and that the endpoint itself is not a sticky datacenter address.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
Failed to connect to 127.0.0.1 port 1080 |
Listener not running, or bound to another port | Start gost -C gost.yaml and check the addr value in the config |
| SOCKS5 authentication failure | Wrong username, password, or endpoint host | Re-copy the credentials from the dashboard and test the endpoint directly with curl |
| Every request times out | Firewall blocking outbound access to the endpoint port, or your source IP is not authorised | Test the raw endpoint without the configurator, then allow the connection in your firewall |
| The reported IP is your own | The app is bypassing the listener, or you used socks5:// instead of socks5h:// |
Point the app at 127.0.0.1:1080 and switch the scheme to socks5h |
| The IP never changes | A single node with no selector, or a sticky datacenter endpoint | Add a selector with several nodes, or move the hop to a rotating residential endpoint |
| Chaining works but is slow | Two hops double the round-trip time | Drop to one hop, or place the entry hop closer to your own region |
| Config edits have no effect | An older process is still running | Restart the service with systemctl restart gost, or stop the terminal process and start it again |
Summary
- A local SOCKS5 configurator, built here with gost, gives every application on the machine one proxy endpoint at
127.0.0.1:1080, whether or not the app supports proxies. - One hop gives you stable egress; two hops give you country-to-country routing, with the exit endpoint address being the one sites see.
- Selectors rotate across several endpoints inside a hop, while a rotating residential endpoint handles rotation on the provider side.
- Use the
socks5hscheme so DNS is resolved by the proxy, and verify the result with a repeatedcurlloop and a geolocation lookup. - Keep the YAML file at
0600and run the listener as a service so it survives reboots and logouts.