ProxyCap forces chosen Windows programs through a proxy using rules, so an app with no proxy setting still leaves from your proxy's IP. The setup is three parts: a proxy entry with the host, port, username and password from your order, a rule that tunnels the app's executable through it, and remote name resolution so DNS goes the same way. Before you set any of it up, know that the publisher now ships a successor.
ProxyCap is now NetDetour
The publisher's page says ProxyCap "has been superseded by NetDetour". What that means in practice, from the same page:
- ProxyCap still receives technical support, compatibility updates and bug fixes "for the time being".
- With an active ProxyCap updates and support subscription, NetDetour accepts your ProxyCap licence key as a free upgrade.
- The
prs2npsxtool converts a ProxyCap configuration to NetDetour's format. Run it before you uninstall ProxyCap. - NetDetour stores its configuration as XML; ProxyCap used a binary format, so NetDetour configs can be reviewed and diffed.
The feature differences that matter for proxy work:
| ProxyCap | NetDetour | |
|---|---|---|
| SOCKS, HTTPS and HTTP proxies | Yes | Yes |
| SSH as a proxy | Yes | Yes |
| Shadowsocks | Yes | No |
| UDP | Only via SOCKS | Only block |
| Remote DNS | Yes | Yes |
ProxyCap's own documentation now redirects to NetDetour, so the labels below are NetDetour's, from its quick-start guide and knowledge base. On an existing ProxyCap install the same three settings exist, but we could not check ProxyCap's own button names, so those steps are described by what they do.
Before you start
- Open your order in the dashboard at https://app.proxyhive.io and copy HOST, PORT, USERNAME and PASSWORD.
- Pick the proxy type: SOCKS5 for any TCP app, or HTTPS for web traffic. Skip the regular HTTP type unless the app only ever speaks plain
http://; NetDetour limits it to unencrypted HTTP, and HTTPS connections need a proxy of another type. - Turn off any proxy configured inside the app itself, so connections are not proxied twice.
Add the proxy
In NetDetour:
- Open NetDetour from its system tray icon (it may be in the hidden icons).
- Click Proxifying Settings in the toolbar.
- Choose the proxy type from the drop-down and click Add.
- Enter a name, then HOST and PORT from your order.
- Tick the authentication box and enter USERNAME and PASSWORD. NetDetour supports username and password for both HTTP-family and SOCKS5 proxies.
- Click OK.
In ProxyCap, the equivalent is adding a proxy server entry in its configuration with the same type, host, port and credentials.
Rules per app
Still in Proxifying Settings, open the Rules tab and click Quick Add Program, then select the app's .exe and click Open. That creates a rule of the Tunnel through proxy type for the program. Click OK in the dialog to save.
Rules run top to bottom, and the first rule that matches wins; nothing below it is checked. Use Move Up and Move Down to put narrow rules (one program, one destination) above broad ones. To give two apps different exits, add two proxy entries and one rule per app pointing at each.
ProxyCap uses the same model: a rule names the program and the action that sends it through your proxy, and rule order decides which one applies.
Resolve names through the proxy
Select Resolve names remotely in NetDetour's DNS settings. Lookups then happen at the proxy, which keeps them from leaving your own network and makes geo-aware DNS answer for the exit's location. NetDetour's own note: Windows and browsers cache DNS, so an old lookup can show up in a leak test after you switch it on. ProxyCap has the same remote DNS option; set it before you test.
Verify the exit IP
Make sure a rule covers your browser, open https://api.ipify.org?format=json and compare the ip with the IP on your order. To rule out the rule itself, check the proxy from a terminal with curl. If your first rule written for a hostname has no effect in a browser, restart the browser completely: NetDetour's knowledge base traces this to the browser's own DNS cache, and later hostname rules apply without a restart.
With ProxyHive
Desktop apps that sign in to accounts want the same address every time. An ISP proxy is a static address registered to a consumer internet provider, with the carrier named and the location chosen at checkout, sold from a single IP, with HTTP, HTTPS and SOCKS5 and username and password authentication, which is everything a ProxyCap or NetDetour entry asks for. If you would rather use a tool with a per-app rule editor on macOS too, Proxifier is the other common choice.