A PAC file defines one function, FindProxyForURL(url, host), which the browser calls before every request. It returns a string naming where to send it:

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".example.com")) {
    return "PROXY HOST:PORT";
  }
  return "DIRECT";
}

PROXY host:port sends the request through an HTTP proxy, SOCKS5 host:port through a SOCKS5 proxy, and DIRECT skips the proxy. Several entries separated by semicolons act as a fallback list, tried in order.

Why use one

A PAC file routes only the traffic you choose: a proxy for the sites you test or research, a direct connection for everything else. It is the browser's answer to NO_PROXY, with more expressive rules. Operating systems accept one under names like "Automatic proxy configuration" on macOS or "Use setup script" on Windows, pointing at a URL that serves the file, ideally as application/x-ns-proxy-autoconfig.

Limits

  • No credentials. A PAC file can name a proxy but cannot carry a username or password. The browser prompts, or you authorise your address with an IP allowlist.
  • Browsers only, mostly. curl, Python and most scraping libraries ignore PAC files.
  • Debugging is awkward. A syntax error usually fails silently, and browsers cache the result.

Common confusion

WPAD is the protocol some networks use to discover a PAC file automatically; the PAC file is the script itself. For per-site routing in a single browser, extensions such as ZeroOmega and FoxyProxy give you the same rules through a settings screen, and can store credentials.