Search1API
Proxies

Proxy troubleshooting

Diagnose proxy errors by the exact response you get, including 407, 403 Tunnel Failed, 503, timeouts, blocked ports, and unexpected IP changes.

Start by running the request with curl in verbose mode. It shows whether the problem is in reaching the proxy, signing in to it, or reaching the target site.

curl -v -x "http://USERNAME:PASSWORD@HOST:PORT" https://ipinfo.io/json

Lines beginning with < after CONNECT are the proxy's response. A 200 Connection Established means the proxy accepted you. Any later error comes from the target site.

Read the proxy's response

The words after the status code tell you which side failed. Tunnel Failed means your credentials were accepted, but the route to the target did not open. Any other text means the proxy itself refused the connection.

Response lineWhat it meansGo to
407 Proxy Authentication RequiredThe username or password is wrong.Sign-in errors
503 Service UnavailableThe traffic allowance is used up, or the proxy has expired or been canceled.Account and allowance
403 Tunnel FailedThe target port or site is not allowed.Blocked ports and sites
502 Tunnel FailedThe route did not answer within 15 seconds, or it is temporarily unreachable.Timeouts
503 Tunnel FailedThis IP is temporarily over its limits.Rate and concurrency limits

The same errors look like this in common clients:

ClientSign-in errorRoute error (Tunnel Failed)
curl, HTTP proxycurl: (56) CONNECT tunnel failed, response 407curl: (56) CONNECT tunnel failed, response 403 (or 502, 503)
curl, SOCKS5User was rejected by the SOCKS5 server (1 1).Can't complete SOCKS5 connection to HOST. (5)
Python requestsTunnel connection failed: 407 Proxy Authentication RequiredTunnel connection failed: 403 Tunnel Failed
Node.js undiciProxy response (407) !== 200 when HTTP TunnelingProxy response (403) !== 200 when HTTP Tunneling

SOCKS5 has no status codes. Every route failure comes back as reply 5 ("connection refused"). To see the exact reason, run the same request once through the HTTP endpoint.

Sign-in errors (407)

The proxy did not accept your username or password. Common causes:

  • Routing parameters were added to the username. They belong on the password.
  • The country code is lowercase, or a session ID is not exactly 8 digits.
  • A suffix was added to a static ISP password. Static ISP proxies take no parameters.
  • The Search1API API key was used as the password.
  • Characters such as @, :, or # in the password are not URL-encoded in the proxy URL.

Copy the connection again from the dashboard, or use the code under Quick start on the proxy page. It is already encoded. Check the format in Rotating proxy parameters.

A client that keeps retrying with a bad password only collects more 407 errors. Stop and fix the credentials first.

Account and allowance (503)

503 Service Unavailable, or a SOCKS5 connection that closes before any reply, means the proxy is refusing new connections for this order:

  • The rotating traffic allowance for this billing period is used up.
  • The proxy has expired or been canceled, and its port was released.

Check Bandwidth and the status on the proxy page. Traffic resumes in the next billing period or after you renew.

Blocked ports and sites (403 Tunnel Failed)

This is the most common route error. Your credentials are fine, but the target is not allowed.

Ports. Static ISP proxies are built for web traffic. Ports 80 and 443 work on every IP. Other ports may be refused with 403 Tunnel Failed on some or all IPs. These include push notifications (5228), SSH (22), DNS over TLS (853), alternative web ports (8080, 8081, 8443), and game or app ports. Outbound email (SMTP, port 25) is not available.

Sites. Some site categories are restricted: banking and payments, crypto exchanges, and some government sites.

To confirm, test https://ipinfo.io/json. If it works and your target does not, the target is blocked. Retrying will not help: the same port or site fails the same way every time.

Do not use a proxy as a whole-device VPN

If you add the proxy to Clash, Shadowrocket, Surge, or a system proxy setting in global mode, every app on the device sends its traffic through it. That includes push services, DNS, telemetry, and background sync. Most of that traffic uses blocked ports, so it fails, uses up concurrency, and can get the IP throttled. Use rule mode, and send only the sites you work with through the proxy.

Timeouts (502 Tunnel Failed)

The proxy waits up to 15 seconds for the route to the target to open. If it does not open in time, you get 502 Tunnel Failed, or SOCKS5 reply 5.

  • Set your client's connect timeout to at least 30 seconds. With a shorter timeout, your client gives up first and you only see a generic timeout.
  • Retry on a new connection, with backoff.
  • If one static IP keeps timing out on sites that work elsewhere, request a replacement from the dashboard's Help page.
  • On a rotating gateway, try the global pool or another country.

Rate and concurrency limits (503 Tunnel Failed)

503 Tunnel Failed means this IP is temporarily over its limits. This usually happens during bursts of many parallel connections, or after very high monthly traffic on one IP.

  • On static ISP Pro and Premium, keep each IP under about 90 concurrent connections. Above 100, new connections may be refused.
  • On static ISP Pro and Premium, an IP that goes over about 100 GB in a month may be throttled until the billing period ends.
  • Reuse connections with keep-alive instead of opening one per request, and spread heavy jobs across more IPs.
  • Back off when you see this error. Retrying immediately keeps the IP over its limit.

Other connection problems

SymptomLikely causeFix
Connection refused or a timeout while connecting to the proxyWrong Host or Port (for example, the Exit IP instead of the Host, or a port from an old order). The proxy has expired and its port was released. Your network blocks the outbound port.Use the Host and Port shown in the dashboard now. Test from another network to rule out a local firewall.
SSL routines::wrong version number or a similar TLS error on the proxyThe proxy URL starts with https://.Use http:// for the proxy URL, even when the target site uses HTTPS.
SOCKS5 connects, but the target fails or resolves to 198.18.x.xWith socks5:// your machine resolves DNS, and local proxy software (for example Clash in fake-IP mode) returns a fake address.Use socks5h:// so DNS is resolved on the proxy side.
200 Connection Established, then the site returns 403, a CAPTCHA, or a block pageThe site detected automated traffic. The proxy is working.Slow down, send realistic headers, and use a sticky session for multi-step flows. For sites that block rotating pools, try a static ISP proxy.

IP and location

SymptomLikely causeFix
The rotating IP does not changeYour client reuses one connection, and a new IP is picked only for a new connection.Open a new connection for each request, or use a new session ID. See How rotation works.
A sticky IP changes before the TTL endsThe session ID changed, the TTL expired, or the residential IP went offline.Reuse the same session ID. For one IP that never changes, use a static ISP proxy.
The country is not the one you choseThe country was set after copying the connection, so the copied password has no _country- parameter.Set Exit country first, then copy, and check that the password contains _country-CC.
IP checkers report different countries or typesEach IP database uses its own sources and refresh schedule.Compare several checkers. On static ISP proxies, the IP details page shows results from four providers.

Connections that drop

  • Connections idle for 5 minutes are closed. Reconnect, or send traffic regularly on long-lived connections.
  • When the rotating allowance runs out, open connections are closed and new ones get 503 Service Unavailable.
  • Static ISP Basic includes 80 GB per IP per month.

Contact support

Open the dashboard's Help page and choose Proxies as the topic. Include the proxy instance ID, the protocol, the time of the failure with its time zone, the target domain and port, and the curl -v output with the password removed.

On this page