Free proxies are proxy servers anyone can use without paying, usually found on public free proxy lists. Most of the addresses on those lists are misconfigured servers, compromised devices, or proxies run on purpose by someone who wants to see the traffic. They are fine for a throwaway, logged-out request with certificate checks left on. They are not safe for logins, personal data, work systems or any scraping you need to rely on.

That is not a scare line. The largest public study we know of, An Extensive Evaluation of the Internet's Open Proxies (Mani, Vaidya, Dworken and Sherr, ACSAC 2018), sent 13 million requests through more than 107,000 listed open proxies over 50 days. It found that more than 92% of the proxies on aggregator sites did not answer at all, and among the ones that did, it observed HTML rewritten to mine cryptocurrency, TLS man-in-the-middle attempts, and malware injected into downloaded files. The study is from 2018; the incentives behind it have not changed.

This guide explains where free proxy lists come from, what can go wrong, how to test a free proxy with the least exposure if you must, and what the paid alternative costs.

What a free proxy list is and where the IPs come from

A free proxy list is a page or feed of IP:PORT pairs, often with a country, a protocol, an "anonymity level" and a last-checked time. The lists are built by software that scans large parts of the internet for ports that answer like a proxy (common ones are 3128, 8080 and 1080), then re-checks them every few minutes because most die quickly.

What the scanner finds falls into four groups, and the list does not tell you which one you are using:

  1. Misconfigured servers. A proxy that a company or a person set up for their own use and left open to the internet: a caching proxy without access rules, a router with a remote-access feature switched on. The owner did not mean to give it to you, and is paying for your traffic.
  2. Compromised devices. Home routers, cameras and servers infected with malware that turns them into proxies. Your traffic leaves through the connection of someone who does not know it is happening.
  3. Proxies run on purpose to collect traffic. Free is a business model when the product is your data: injected ads, harvested credentials, or a record of what people browse.
  4. Deliberately public proxies. A few are run openly by people or projects who mean to share them. They exist; they are a small part of what the lists carry, and they look the same from the outside.

If you are new to how a proxy sits between you and a site, what is a proxy server covers the basics first.

Are free proxies safe? What can go wrong

A proxy is a machine that handles every byte of your request. With a paid provider you have a contract, a company and published rules. With a free proxy you have an address.

Plain HTTP can be read and rewritten

Anything sent over http:// passes through the proxy in the clear. The operator can read the page, the form you submit and any cookie or password in it, and can change the response on the way back: add a script, swap a link, replace an ad. The study above caught proxies doing exactly this.

HTTPS protects you only if you let it

For https:// sites, a well-behaved proxy opens a tunnel (the CONNECT method) and passes encrypted bytes it cannot read. A hostile one tries to present its own certificate instead. Your browser or HTTP client will refuse that certificate, unless you have told it not to check.

Scraping code often does: verify=False in Python requests, -k in curl, --ignore-certificate-errors in a browser. Those flags turn a failed attack into a successful one. Never combine them with a proxy you do not control.

The operator sees where you go

Even with a tunnel, the proxy sees which host you connect to and when, and how much you send. This is what a proxy logged when we ran the test script further down through our own local proxy on 2026-09-30:

CONNECT api.ipify.org:443 - 3541 bytes - 267.40ms
GET httpbin.org:80/headers - 200 OK - 465 bytes - 245.38ms
GET httpbin.org:80/html - 200 OK - 3980 bytes - 270.27ms

For HTTPS it logged the host; for plain HTTP, the full URL and status. A free proxy's operator can keep all of it.

Your own IP can leak

Some open proxies are "transparent": they forward your request with a header such as X-Forwarded-For that contains your real address. The target sees both. The "anonymity level" column on free lists is meant to flag this, but it is only as current as the last check.

The IPs are already burned

Free proxy lists are public, which means the sites you target can read them too. Anti-bot systems and IP reputation services collect these addresses, and many sites block them outright. You spend time filtering a list for proxies that answer, and then find the ones that answer are blocked. For scraping, that alone usually ends the experiment. Avoiding blocks when scraping explains how IP reputation is scored.

Downloads can be swapped

A proxy that rewrites HTML can rewrite a file too. The study found binaries modified in transit. Never download software, packages or updates through a proxy you do not trust, even over a connection that looks fine.

This is not legal advice. The honest answer is that it depends on the proxy and on where you are.

Using a proxy that its operator publishes for public use is generally a different matter from using one that is open by accident. A misconfigured company server or a hacked home router was never offered to you, and in many countries using a computer without its owner's authorisation is an offence under computer misuse laws, whether or not a password was in the way. You also cannot know which kind you are on. What you do through any proxy is still your responsibility, including the terms of the sites you visit.

If you use a paid provider, its rules on what you may target should be published before you pay. Ours are on the allowed-use page.

How to test a free proxy safely, if you must

Sometimes you need to check one: a proxy from a list, one a colleague found, or one a tool configured for you. Keep the exposure as small as possible.

1. Use a disposable environment

Run the test in a throwaway container or virtual machine, not on your laptop's main profile. No saved passwords, no logged-in browser, no SSH keys, no company VPN.

2. Send nothing you would mind losing

Only request public test endpoints that echo back what they receive. No logins, no cookies, no API keys, no personal data.

3. Leave certificate checks on

If HTTPS through the proxy fails with a certificate error, that is the answer: the proxy is intercepting. Do not "fix" it with verify=False or -k.

4. Check the exit IP, the headers and the content

This Python script does all three with requests. It checks that HTTPS works with verification on, that the exit IP is not yours, whether your IP appears in forwarded headers, which headers the proxy added, and whether a plain-HTTP page arrives byte for byte the same as it does directly.

import hashlib
import sys

import requests

PROXY = sys.argv[1]
PROXIES = {"http": PROXY, "https": PROXY}
TIMEOUT = 15


def get(url, proxied):
    return requests.get(url, proxies=PROXIES if proxied else None, timeout=TIMEOUT)


def main():
    my_ip = get("https://api.ipify.org?format=json", False).json()["ip"]

    try:
        exit_ip = get("https://api.ipify.org?format=json", True).json()["ip"]
    except requests.exceptions.SSLError:
        print("FAIL  TLS certificate did not verify: the proxy is intercepting HTTPS")
        return
    except requests.exceptions.RequestException as err:
        print(f"FAIL  no answer through the proxy: {type(err).__name__}")
        return
    print(f"{'FAIL' if exit_ip == my_ip else 'ok  '}  exit IP {exit_ip} (yours is {my_ip})")

    direct = get("http://httpbin.org/headers", False).json()["headers"]
    proxied = get("http://httpbin.org/headers", True).json()["headers"]
    added = sorted(set(proxied) - set(direct) - {"X-Amzn-Trace-Id"})
    leaks = my_ip in str(proxied)
    print(f"{'FAIL' if leaks else 'ok  '}  your IP {'appears' if leaks else 'does not appear'} in forwarded headers")
    print(f"{'warn' if added else 'ok  '}  headers the proxy added: {added or 'none'}")

    page = "http://httpbin.org/html"
    same = hashlib.sha256(get(page, False).content).digest() == hashlib.sha256(get(page, True).content).digest()
    print(f"{'ok  ' if same else 'FAIL'}  plain-HTTP page {'unchanged' if same else 'was modified in transit'}")


main()

Run it with the proxy URL:

python check_proxy.py http://203.0.113.10:8080

We ran it on 2026-09-30 against three proxies on our own machine: an ordinary proxy, one we had set up to rewrite a word in the HTTP page, and an address with nothing listening. The rewriting proxy produced FAIL plain-HTTP page was modified in transit, and the dead one FAIL no answer through the proxy: ProxyError. Against a proxy running on your own machine, the exit IP line also fails, because the exit is your own address; against a remote proxy it should show someone else's.

A clean result is not a clean bill of health. A proxy can behave for a test and misbehave later, or only on certain sites. The script finds the careless ones.

5. Throw it away

When you are done, delete the container. Do not move the proxy into anything long-lived.

If you only need a proxy to learn or test code, run your own

A lot of free-proxy searches come from developers who want to see how proxy settings work, or to test that their scraper handles a proxy at all. For that, the safest free proxy is one on your own machine:

pip install proxy.py
proxy --hostname 127.0.0.1 --port 18100 --basic-auth user:pass

Point your code at http://user:[email protected]:18100 and you have an authenticating proxy that logs every request, which is how we test the snippets in our guides. It will not give you a different IP, but it shows you exactly what your code sends. HTTP vs SOCKS5 proxies explains what changes when you switch protocol.

For privacy rather than scraping, a free proxy is the wrong tool; proxy vs VPN covers what each one protects.

Free proxy list vs a paid proxy: the cheaper-than-it-looks option

The cost of free proxies is not zero. It is the hours spent filtering lists for addresses that answer, the requests that fail on blocked IPs, the retries, and the risk of everything above. For a job you need to finish, a small paid order is usually cheaper once you count your time.

A paid proxy does not have to be a big commitment:

  • A new ProxyHive account gets 1 GB of residential traffic free, enough to run your own targets and see the success rate before you pay.
  • After that, the minimum top-up is $10, and the traffic you buy never expires, so a small balance does not turn into a monthly bill.
  • Residential starts at $5.50/GB for 1 GB on our residential pricing page, with no plan to cancel.
  • If you need a fixed address instead, ISP proxies are sold from a single IP at $3.20/IP a month.

We are not the only option, and we say where others are cheaper in our residential proxy price comparison. Whoever you pick, choose a provider that publishes its prices, its rules and who you are dealing with. That is the difference between a proxy and an address on a list.