Deluge's proxy page is Edit > Preferences > Proxy. Set the type to Socks5 Auth, enter the host, SOCKS5 port, username and password from your order, and you are done: unlike qBittorrent, Deluge turns on Proxy Peers, Proxy Trackers and Proxy Hostnames by default. We confirmed both halves of that on 2026-10-08, from a fresh configuration file and from the socket table of a running daemon.
The proxy is not a VPN and does not encrypt anything; the wiki of qBittorrent, a client on the same engine, sends people worried about copyright trouble to a VPN instead. Treat our SOCKS5 as TCP only: we do not advertise UDP relay, so DHT, UDP trackers and uTP will not work through it even though Deluge's engine would relay them over a proxy that allowed it. An HTTP proxy carries no UDP at all. Anything that leaves outside the proxy uses your own IP. Residential traffic is billed per GB, as is traffic beyond a shared IP's included gigabyte, and a seeded torrent pushes its payload through twice; the terms say what is counted. Unauthorised sharing through our proxies is not allowed under the allowed-use policy.
What our run showed
We ran Deluge 2.2.0 with libtorrent 2.0.11 (Alpine Linux 3.22 packages) in a Docker container. The SOCKS5 server was Dante 1.4.4 with username and password, refusing UDP ASSOCIATE and BIND.
First, the defaults. A fresh core.conf written by the daemon contained:
{"anonymous_mode": false, "force_proxy": false, "hostname": "", "password": "", "port": 8080,
"proxy_hostnames": true, "proxy_peer_connections": true, "proxy_tracker_connections": true,
"type": 0, "username": ""}
Then we changed only the type (3, Socks5 Auth), host, port, username and password, restarted the daemon, added the Debian 13.7.0 netinst torrent with a 1 MiB/s cap, waited 90 seconds and measured for 60.
| Measurement | Socks5 Auth set | A run with type None, for contrast |
|---|---|---|
| Established TCP connections through the proxy | 196 of 196 | 0 of 24 |
| uTP packets the client sent to internet hosts in 60 s | 0 | 73,927, to 209 hosts |
| DHT packets sent in 60 s | 0 | 2,036, to 481 hosts |
| DHT nodes reported | 0 | 324 |
| Proxy log | Authenticated connects; one UDP ASSOCIATE refused | nothing |
The download ran at the cap in both cases, from 186 seeds through the proxy. The difference is in who saw our address: in the proxied run, only the proxy.
Socks5 or Socks5 Auth
Deluge splits authentication into separate types: None, Socks4, Socks5, Socks5 Auth, HTTP, HTTP Auth and I2P. Only the two Auth types send a username and password.
- With username and password on the order, choose Socks5 Auth.
- With an IP allowlist on the order, plain Socks5 works and keeps the password out of
core.conf, which stores it in plain text. Username and password vs allowlist covers the trade-off. - HTTP Auth also proxies peers, through CONNECT, if the proxy allows CONNECT to the ports peers listen on. It can never carry UDP.
The daemon is where the proxy lives
Deluge's GTK, Web UI and console clients all drive a daemon, deluged, and the proxy is part of the daemon's configuration: it sits in core.conf beside the daemon, which is where we set it. On a home server with a thin client on a laptop, the proxy applies on the server, and the socket table to check is the server's. Edit core.conf only with the daemon stopped, or use the client so the daemon writes it.
The other boxes
- Proxy Hostnames: resolve tracker names through the proxy. Keep it on.
- Force Proxy Use: maps to libtorrent's
force_proxy, deprecated since libtorrent 1.2 with the note "when set, the proxy is always used". The source suggests that on current builds the box adds nothing; we did not test it. - Hide Client Identity: the tooltip says "Attempt to hide client identity and only use proxy for incoming connections." The proxy settings also carry an
anonymous_modekey, off on a fresh install; libtorrent's anonymous mode changes what the client says about itself, not where traffic goes.
Measure your own daemon
On the machine running deluged:
PROXY=203.0.113.10:1080
ss -Htnp state established | grep deluged \
| awk -v p="$PROXY" '$4 == p { via++ } $4 != p { direct++ } END { print "via proxy:", via+0, "direct:", direct+0 }'
ss -Huanp | grep deluged
The second line prints the UDP listening port; sudo tcpdump -ni any -c 50 udp port THAT_PORT should then show nothing leaving for public addresses. Compare the exit IP with the curl line from our proxy checker.
What the plugin-driven seedbox costs
Deluge is a common choice for a headless seeding box, with plugins such as Label and Scheduler doing the work. On a meter, seeding is the expensive half: a 50 GB set of open datasets seeded to a ratio of 1.0 is 100 GB through the proxy, $265.00 on residential at checkout. An ISP IP is $3.20/IP (dedicated) a month and a datacenter IP $1.90/IP (dedicated), both with no bandwidth cap, though port speed and fair-use terms still apply. Peer-to-peer traffic for lawful content is fine on residential and on dedicated ISP and datacenter IPs, which carry no traffic meter. The cost calculator does the comparison for your own volume. Two keys in the same core.conf bound the bill whichever way you pay: max_upload_speed, unlimited on a fresh install, and stop_seed_at_ratio with stop_seed_ratio, off and 2.0 on a fresh install.
Deluge behind a proxy accepts no incoming connections, so it reaches only peers that accept them; router port forwarding does nothing for proxied peers. The torrent client comparison shows which other clients behave the same way.