Proxy troubleshooting
Diagnose proxy errors by the exact response you get, including 407, 403 Tunnel Failed, 503, timeouts, blocked ports, and unexpected IP changes.
Start by running the request with curl in verbose mode. It shows whether the problem is in reaching the proxy, signing in to it, or reaching the target site.
curl -v -x "http://USERNAME:PASSWORD@HOST:PORT" https://ipinfo.io/jsonLines beginning with < after CONNECT are the proxy's response. A 200 Connection Established means the proxy accepted you. Any later error comes from the target site.
Read the proxy's response
The words after the status code tell you which side failed. Tunnel Failed means your credentials were accepted, but the route to the target did not open. Any other text means the proxy itself refused the connection.
| Response line | What it means | Go to |
|---|---|---|
407 Proxy Authentication Required | The username or password is wrong. | Sign-in errors |
503 Service Unavailable | The traffic allowance is used up, or the proxy has expired or been canceled. | Account and allowance |
403 Tunnel Failed | The target port or site is not allowed. | Blocked ports and sites |
502 Tunnel Failed | The route did not answer within 15 seconds, or it is temporarily unreachable. | Timeouts |
503 Tunnel Failed | This IP is temporarily over its limits. | Rate and concurrency limits |
The same errors look like this in common clients:
| Client | Sign-in error | Route error (Tunnel Failed) |
|---|---|---|
| curl, HTTP proxy | curl: (56) CONNECT tunnel failed, response 407 | curl: (56) CONNECT tunnel failed, response 403 (or 502, 503) |
| curl, SOCKS5 | User was rejected by the SOCKS5 server (1 1). | Can't complete SOCKS5 connection to HOST. (5) |
Python requests | Tunnel connection failed: 407 Proxy Authentication Required | Tunnel connection failed: 403 Tunnel Failed |
Node.js undici | Proxy response (407) !== 200 when HTTP Tunneling | Proxy response (403) !== 200 when HTTP Tunneling |
SOCKS5 has no status codes. Every route failure comes back as reply 5 ("connection refused"). To see the exact reason, run the same request once through the HTTP endpoint.
Sign-in errors (407)
The proxy did not accept your username or password. Common causes:
- Routing parameters were added to the username. They belong on the password.
- The country code is lowercase, or a session ID is not exactly 8 digits.
- A suffix was added to a static ISP password. Static ISP proxies take no parameters.
- The Search1API API key was used as the password.
- Characters such as
@,:, or#in the password are not URL-encoded in the proxy URL.
Copy the connection again from the dashboard, or use the code under Quick start on the proxy page. It is already encoded. Check the format in Rotating proxy parameters.
A client that keeps retrying with a bad password only collects more 407 errors. Stop and fix the credentials first.
Account and allowance (503)
503 Service Unavailable, or a SOCKS5 connection that closes before any reply, means the proxy is refusing new connections for this order:
- The rotating traffic allowance for this billing period is used up.
- The proxy has expired or been canceled, and its port was released.
Check Bandwidth and the status on the proxy page. Traffic resumes in the next billing period or after you renew.
Blocked ports and sites (403 Tunnel Failed)
This is the most common route error. Your credentials are fine, but the target is not allowed.
Ports. Static ISP proxies are built for web traffic. Ports 80 and 443 work on every IP. Other ports may be refused with 403 Tunnel Failed on some or all IPs. These include push notifications (5228), SSH (22), DNS over TLS (853), alternative web ports (8080, 8081, 8443), and game or app ports. Outbound email (SMTP, port 25) is not available.
Sites. Some site categories are restricted: banking and payments, crypto exchanges, and some government sites.
To confirm, test https://ipinfo.io/json. If it works and your target does not, the target is blocked. Retrying will not help: the same port or site fails the same way every time.
Do not use a proxy as a whole-device VPN
If you add the proxy to Clash, Shadowrocket, Surge, or a system proxy setting in global mode, every app on the device sends its traffic through it. That includes push services, DNS, telemetry, and background sync. Most of that traffic uses blocked ports, so it fails, uses up concurrency, and can get the IP throttled. Use rule mode, and send only the sites you work with through the proxy.
Timeouts (502 Tunnel Failed)
The proxy waits up to 15 seconds for the route to the target to open. If it does not open in time, you get 502 Tunnel Failed, or SOCKS5 reply 5.
- Set your client's connect timeout to at least 30 seconds. With a shorter timeout, your client gives up first and you only see a generic timeout.
- Retry on a new connection, with backoff.
- If one static IP keeps timing out on sites that work elsewhere, request a replacement from the dashboard's Help page.
- On a rotating gateway, try the global pool or another country.
Rate and concurrency limits (503 Tunnel Failed)
503 Tunnel Failed means this IP is temporarily over its limits. This usually happens during bursts of many parallel connections, or after very high monthly traffic on one IP.
- On static ISP Pro and Premium, keep each IP under about 90 concurrent connections. Above 100, new connections may be refused.
- On static ISP Pro and Premium, an IP that goes over about 100 GB in a month may be throttled until the billing period ends.
- Reuse connections with keep-alive instead of opening one per request, and spread heavy jobs across more IPs.
- Back off when you see this error. Retrying immediately keeps the IP over its limit.
Other connection problems
| Symptom | Likely cause | Fix |
|---|---|---|
Connection refused or a timeout while connecting to the proxy | Wrong Host or Port (for example, the Exit IP instead of the Host, or a port from an old order). The proxy has expired and its port was released. Your network blocks the outbound port. | Use the Host and Port shown in the dashboard now. Test from another network to rule out a local firewall. |
SSL routines::wrong version number or a similar TLS error on the proxy | The proxy URL starts with https://. | Use http:// for the proxy URL, even when the target site uses HTTPS. |
SOCKS5 connects, but the target fails or resolves to 198.18.x.x | With socks5:// your machine resolves DNS, and local proxy software (for example Clash in fake-IP mode) returns a fake address. | Use socks5h:// so DNS is resolved on the proxy side. |
200 Connection Established, then the site returns 403, a CAPTCHA, or a block page | The site detected automated traffic. The proxy is working. | Slow down, send realistic headers, and use a sticky session for multi-step flows. For sites that block rotating pools, try a static ISP proxy. |
IP and location
| Symptom | Likely cause | Fix |
|---|---|---|
| The rotating IP does not change | Your client reuses one connection, and a new IP is picked only for a new connection. | Open a new connection for each request, or use a new session ID. See How rotation works. |
| A sticky IP changes before the TTL ends | The session ID changed, the TTL expired, or the residential IP went offline. | Reuse the same session ID. For one IP that never changes, use a static ISP proxy. |
| The country is not the one you chose | The country was set after copying the connection, so the copied password has no _country- parameter. | Set Exit country first, then copy, and check that the password contains _country-CC. |
| IP checkers report different countries or types | Each IP database uses its own sources and refresh schedule. | Compare several checkers. On static ISP proxies, the IP details page shows results from four providers. |
Connections that drop
- Connections idle for 5 minutes are closed. Reconnect, or send traffic regularly on long-lived connections.
- When the rotating allowance runs out, open connections are closed and new ones get
503 Service Unavailable. - Static ISP Basic includes 80 GB per IP per month.
Contact support
Open the dashboard's Help page and choose Proxies as the topic. Include the proxy instance ID, the protocol, the time of the failure with its time zone, the target domain and port, and the curl -v output with the password removed.