Common proxy errors and how to fix them — 407, timeouts, ERR_PROXY_CONNECTION_FAILED
In this article
- 01 Before fixing anything: try curl
- 02 407 Proxy Authentication Required
- 03 ERR_PROXY_CONNECTION_FAILED: can't reach the proxy
- 04 ERR_TUNNEL_CONNECTION_FAILED: the proxy can't open a tunnel
- 05 Wrong protocol and SOCKS errors
- 06 Timeouts and slow proxies
- 07 I rotated, but the IP didn't change
- 08 Out of bandwidth or the plan has expired
- 09 The website blocks you or keeps showing captchas
Most proxy errors come down to a handful of familiar causes: a wrong password, a wrong port, the wrong protocol, or checking too soon after a rotation. This guide lists the messages you'll see in browsers, in curl and in tools, explains what each one means, and gives the fixes in the order worth trying.
Before fixing anything: try curl
When a tool says "proxy error", try the same proxy with curl. If curl works, the problem is in how the tool is set up; if curl fails too, the problem is in the proxy details or the network:
curl -v -x "http://USER:PASS@HOST:PORT" https://api.ipify.orgThe -v flag prints every step of the connection, so you can see where it fails. On Windows, type curl.exe rather than curl. If this is your first time testing a proxy, read how to check a proxy as well.
407 Proxy Authentication Required
What it means: the proxy received the connection but refused it because the username or password is wrong. In curl it usually reads CONNECT tunnel failed, response 407; in a browser, the proxy sign-in box keeps coming back.
How to fix it:
- Copy the username and password again from My proxies, watching for stray spaces at the start or end.
- If you use the URL format (
http://USER:PASS@HOST:PORT) and the password has special characters, encode them:@becomes%40,:becomes%3A,/becomes%2F,#becomes%23,?becomes%3F,%becomes%25. In Python useurllib.parse.quote(password, safe=""); in JavaScript,encodeURIComponent(password). - With the
HOST:PORT:USER:PASSformat, a password containing:gets split in the wrong place — fill in each field separately instead of pasting the whole line.
ERR_PROXY_CONNECTION_FAILED: can't reach the proxy
What it means: the browser couldn't open a connection to the proxy server. curl reports the same thing as Failed to connect to … port …, Connection refused or Could not resolve proxy.
How to fix it:
- Double-check the host and port — one wrong digit in the port is enough.
Could not resolve proxymeans the proxy's hostname is mistyped or doesn't resolve: copy the host again.- Check that the plan is still active and the proxy shows as running under My proxies.
- Turn off other VPN or proxy extensions in the browser — they can override your settings.
- Some office or school networks and antivirus programs block outgoing connections to unusual ports. Try another network, such as your phone's hotspot; if that works, the first network is blocking you.
ERR_TUNNEL_CONNECTION_FAILED: the proxy can't open a tunnel
What it means: the browser reached the proxy, but the proxy couldn't open the tunnel (CONNECT) to the website. The usual causes:
- The proxy is rotating and the device hasn't finished reconnecting — wait a few seconds and reload.
- The website can't be reached from the proxy's network at that moment. Try another page such as api.ipify.org to tell a proxy problem from a website problem.
Wrong protocol and SOCKS errors
HTTP and SOCKS5 usually run on two different ports. A SOCKS5 port in an HTTP field (or the reverse) produces confusing errors: the connection closes immediately, an empty reply, or the tool says the proxy is "invalid". Check that the proxy type you picked matches the port.
ERR_SOCKS_CONNECTION_FAILED in Chrome has a special cause: Chrome and Edge don't support SOCKS5 with a password. In regular browsers, use HTTP; for password-protected SOCKS5, use an antidetect browser or a tool that supports it. The full explanation is in SOCKS5 vs HTTP proxies.
In code, if a site won't load over SOCKS5 or loads the wrong regional version, change socks5:// to socks5h:// so the proxy resolves DNS.
Timeouts and slow proxies
What it means: the connection opens, but data arrives too slowly or not before the timeout (curl says Operation timed out).
Causes and fixes:
- You just rotated: a 4G device needs a few seconds to reconnect. In code, retry after a few seconds instead of failing straight away.
- Too many parallel connections through one proxy: reduce the number of workers, or spread the work over several proxies.
- Large downloads: 4G proxies depend on the mobile signal and aren't made for high-speed bulk transfers.
- Timeouts that are too short: on mobile networks, 15–30 seconds per request is more reasonable than a few seconds.
I rotated, but the IP didn't change
This is the most common question with rotating proxies. Work through it in order:
- You checked too soon. Wait a few seconds after calling the rotation link before checking.
- The check didn't go through the proxy. For example, the
-xflag is missing in curl — then you're seeing your home IP. - The browser kept its old connections. Close the browser or antidetect profile completely and reopen it.
- You got the same IP back. A carrier's IP pool is finite, so now and then the new IP matches the previous one. Wait a moment and rotate again.
- You called the link several times in a row. Each call restarts the reconnection; call it once and wait.
How to automate "call the link, then wait for the new IP" is covered in rotating the IP with an API.
Out of bandwidth or the plan has expired
Every 65Proxy plan comes with 200GB of bandwidth and its own term (1 day · 7 days · 1 month). Once a plan expires or its bandwidth is used up, the proxy may stop connecting even though every setting is right. Open My proxies to see each proxy's bandwidth used and expiry date, and pick a new plan if you need one.
The website blocks you or keeps showing captchas
This isn't really a proxy error — the proxy works, but the website doesn't trust your connection. Try, in order:
- Rotate the IP to get away from an IP that's being limited.
- Slow down: send fewer requests and pause between actions.
- Check the browser: does the time zone, WebRTC and fingerprint match the IP? See how to check a proxy.
If you still can't pin it down, note the full error message and the output of the curl -v command at the top of this page: most problems can be narrowed down from those two alone.