A PAC file defines one function, FindProxyForURL(url, host), which the browser calls before every request. It returns a string naming where to send it:
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".example.com")) {
return "PROXY HOST:PORT";
}
return "DIRECT";
}
PROXY host:port sends the request through an HTTP proxy, SOCKS5 host:port through a SOCKS5 proxy, and DIRECT skips the proxy. Several entries separated by semicolons act as a fallback list, tried in order.
Why use one
A PAC file routes only the traffic you choose: a proxy for the sites you test or research, a direct connection for everything else. It is the browser's answer to NO_PROXY, with more expressive rules. Operating systems accept one under names like "Automatic proxy configuration" on macOS or "Use setup script" on Windows, pointing at a URL that serves the file, ideally as application/x-ns-proxy-autoconfig.
Limits
- No credentials. A PAC file can name a proxy but cannot carry a username or password. The browser prompts, or you authorise your address with an IP allowlist.
- Browsers only, mostly. curl, Python and most scraping libraries ignore PAC files.
- Debugging is awkward. A syntax error usually fails silently, and browsers cache the result.
Common confusion
WPAD is the protocol some networks use to discover a PAC file automatically; the PAC file is the script itself. For per-site routing in a single browser, extensions such as ZeroOmega and FoxyProxy give you the same rules through a settings screen, and can store credentials.