What is a proxy server? A proxy server is a computer that sends network requests on your behalf: your program talks to the proxy, the proxy talks to the website, and the website sees the proxy's IP address instead of yours. That is the whole idea. Everything else, from office web filters to scraping networks to the CDN in front of most large sites, is a variation on who runs the middleman and what it does to the traffic on the way through.
This guide covers the three kinds of proxy you will hear about (forward, reverse and transparent), how a request flows through one, what the target can and cannot see, and how to try a proxy from the command line in under a minute.
What is a proxy server, and how does it work?
Without a proxy, your machine opens a TCP connection straight to the website. With a proxy, it opens the connection to the proxy instead and says where it wants to go. The proxy opens a second connection to the target, relays the request, and relays the response back.
Without a proxy:
your client ─────────────────────────────► example.com
(203.0.113.7) sees 203.0.113.7
With a forward proxy:
your client ──────► proxy server ─────────► example.com
(203.0.113.7) (198.51.100.20) sees 198.51.100.20
connection 1 connection 2
Two connections, not one. That detail explains most proxy behaviour: why the target sees the proxy's address, why the proxy can add or strip headers on plain HTTP, why a slow proxy slows everything, and why a proxy's network (home broadband or a data centre) changes how targets treat you.
Forward vs reverse vs transparent proxies
The word "proxy" covers three setups that do different jobs for different people.
| Forward proxy | Reverse proxy | Transparent (intercepting) proxy | |
|---|---|---|---|
| Who runs it | You, or a provider you pay | The website's owner | A network operator: an employer, school, ISP or hotel |
| Who configures the client | You, in your program or OS | Nobody: visitors reach it through DNS | Nobody: the network redirects traffic to it |
| Whose address it replaces | The client's, towards the target | The servers', towards visitors | Usually none; it sits in the path |
| Typical jobs | Scraping, testing from other locations, fixed egress IPs | Load balancing, TLS termination, caching, bot filtering | Web filtering, caching, captive portals |
| Examples | Proxy providers, Squid on your own server | nginx, HAProxy, CDNs such as Cloudflare | Corporate web gateways |
Forward proxy
This is what people mean when they buy proxies. You point a client at it, and every request that client makes leaves from the proxy's address. A forward proxy serves the person sending requests. A proxy provider runs thousands of them, or a gateway in front of a pool, and sells you access.
Reverse proxy
A reverse proxy serves the website. It accepts connections from the whole internet and hands them to servers that are not exposed directly. When you visit a large site you are almost always talking to a reverse proxy first, and that is also where bot protection usually lives. So when you scrape through a forward proxy, the thing judging your request on the other end is often a reverse proxy.
Transparent proxy
Here the client does not know about the proxy. The network sends web traffic through it, often for filtering or caching. The HTTP specification calls this an interception proxy and notes it is "commonly known as a transparent proxy" (RFC 9110, section 3.7). Proxy lists use "transparent" in a second sense, covered below: a proxy that passes your real address on to the target.
How a request flows through an HTTP proxy
An HTTP proxy handles plain HTTP and HTTPS differently.
Plain HTTP
For an http:// URL the client sends the full URL to the proxy, plus a Proxy-Authorization header if the proxy needs credentials. The proxy reads the request, removes the proxy-only headers, and forwards the rest.
We ran a local authenticating proxy (proxy.py 2.4.10) and a small server that prints every header it receives. This is what curl sent to the proxy:
GET http://127.0.0.1:18402/ HTTP/1.1
Host: 127.0.0.1:18402
Proxy-Authorization: Basic dXNlcjpwYXNz
User-Agent: curl/8.5.0
Accept: */*
Proxy-Connection: Keep-Alive
And this is what arrived at the server:
Host: 127.0.0.1:18402
User-Agent: curl/8.5.0
Accept: */*
Via: 1.1 proxy.py v2.4.10
The credentials and Proxy-Connection were stripped, and the proxy announced itself with a Via header. Every proxy makes its own choices here.
HTTPS: the CONNECT tunnel
For an https:// URL the client asks for a tunnel instead. From the same test, with curl -v:
> CONNECT api.ipify.org:443 HTTP/1.1
> Host: api.ipify.org:443
> Proxy-Authorization: Basic dXNlcjpwYXNz
> User-Agent: curl/8.5.0
> Proxy-Connection: Keep-Alive
>
< HTTP/1.1 200 Connection established
After the 200, the proxy copies bytes both ways and the TLS handshake runs between curl and the target. The proxy knows the hostname and port. It cannot read or change the path, headers or body, and it cannot add a Via header to a request it cannot see. Almost all scraping today goes through this tunnel. For how SOCKS5 does the same job a layer lower, see HTTP vs SOCKS5 proxies.
What the target sees: transparent, anonymous and elite proxies
A target learns about your connection from two places: the IP address that connects to it, and any headers a proxy adds to plain HTTP requests. The headers that give a proxy away are:
Via, defined in RFC 9110: names each proxy the request passed through.X-Forwarded-For: not in any RFC, but near universal; carries the original client's IP.Forwarded, the standard form of the same idea from RFC 7239.
Proxy lists grade proxies by what those headers reveal:
| Grade | Target sees your real IP? | Target sees a proxy was used? | What gives it away |
|---|---|---|---|
| Transparent | Yes | Yes | X-Forwarded-For or Forwarded carries your address |
| Anonymous | No | Yes | Via, or a forwarding header with the proxy's own address |
| Elite (high anonymity) | No | Not from headers | Nothing in the headers |
Two things to keep in mind. First, these grades only apply to plain HTTP, because over a CONNECT tunnel the proxy never touches the headers. Second, a clean header set does not make a proxy invisible: targets also look up the IP's network owner, its history and your client's fingerprint. The IP's network matters most, and it is what separates residential, ISP and datacenter proxies.
To check a proxy's headers yourself, request a plain-HTTP echo page through it:
curl -s -x "http://USERNAME:PASSWORD@HOST:PORT" http://ifconfig.me/all.json
ifconfig.me's own front end adds 1.1 google to the via field of every answer, with or without a proxy. Any entry before it came from your proxy, and your own IP in the forwarded field means the proxy is transparent in the proxy-list sense.
What proxy servers are used for
- Web data collection. Spreading requests across many addresses, and sending them from the network type a target accepts. See web scraping proxies.
- Seeing a site from somewhere else. Prices, search results and ads change by location, so teams check them through proxies placed in the right country.
- A fixed egress address. Partner APIs and firewalls that allowlist one IP need your traffic to leave from an address that never changes.
- Separate identities for accounts you own. One stable address per account, where the platform permits several.
- Control and caching inside a network. The corporate and school use of forward and transparent proxies.
Whatever the job, it has to fit the target's rules and ours: the allowed-use policy lists what is fine, what needs a conversation first, and what is banned. This is not legal advice.
What a proxy server does not do
- It does not encrypt your traffic. HTTP and SOCKS5 proxies relay bytes as they are. HTTPS stays encrypted end to end through the tunnel, but the proxy adds nothing. Credentials sent to a plain
http://proxy are base64, not encryption. For an encrypted tunnel for your whole device, proxy vs VPN explains the difference. - It does not cover every program. A proxy set in your scraper does not route your browser, and many programs ignore system proxy settings.
- It does not hide your fingerprint. Your TLS handshake, headers, cookies and behaviour pass through untouched. A proxy changes the address, not the client.
- It does not make you fast. It adds a hop. A good one adds little; a distant or overloaded one adds a lot.
- It is not anonymous from the operator. Whoever runs the proxy can see which hosts you connect to. Choose one you trust, which is also why free public proxy lists are a poor idea for anything with a login.
How to try a proxy server with curl
curl's -x option sends a request through a proxy. Pick any proxy you have credentials for, then compare your address with and without it:
curl -s "https://api.ipify.org?format=json"
curl -s -x "http://USERNAME:PASSWORD@HOST:PORT" "https://api.ipify.org?format=json"
The first line prints your own address, the second the proxy's. If the password contains @, : or /, pass it separately with -U "USERNAME:PASSWORD". Add -v to watch the CONNECT exchange from the section above. The curl integration guide covers SOCKS5, environment variables and error codes.
To try it on ProxyHive, order one datacenter IP from $3.20/IP a month, placed by country, region and city, or one ISP IP from $3.20/IP. The order in your dashboard at app.proxyhive.io lists the host, the HTTP, HTTPS and SOCKS5 ports, the username and the password; paste them into the command above in place of the placeholders and use the HTTP port. The only floor is the $10 minimum top-up, and the datacenter proxy line has the details.