A forward proxy works for the client. You point your browser, script or operating system at it, and it fetches pages on your behalf. The website only sees the proxy's address. Every commercial proxy you can buy for scraping, testing or account work is a forward proxy, and so is the Squid box a company uses to filter its staff's web traffic.
Forward vs reverse
The difference is whose side the proxy is on:
| Forward proxy | Reverse proxy | |
|---|---|---|
| Works for | The client | The website |
| Configured by | You, in your client | The site operator |
| Hides | The client's IP from the site | The site's servers from the client |
| Examples | Scraping proxies, corporate proxies | Nginx, load balancers, CDNs |
When you scrape a large site, both are in play: your forward proxy talks to the site's reverse proxy, which is often where its bot detection runs.
How clients use one
Most tools read the proxy from settings or environment variables:
export HTTP_PROXY=http://USERNAME:PASSWORD@HOST:PORT
export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT
curl "https://api.ipify.org?format=json"
The HTTPS_PROXY name refers to the kind of site you visit, not to how you reach the proxy, which is why its value still starts with http://. Hosts you want to reach directly go in NO_PROXY.
Common confusion
A forward proxy is configured per application, and only the traffic you send to it goes through it. That is the main practical difference from a VPN, which captures the whole device; proxy vs VPN covers when each fits.