Proxy checker
What websites see when this browser connects
Turn your proxy on and press the button. The page shows the address a site sees, the network it belongs to, whether WebRTC hands a page a second address, and any header that names a proxy.
Nothing is sent until you press the button. Then your browser makes three requests: to our API at api.proxyhive.io, which returns your address, a short list of proxy-revealing headers and your user agent; to ipapi.is with that address, for the network lookup; and over WebRTC to Google's STUN server, which replies with the address it sees. We don't store the result.
What each check reads
Address. Our API reports the address your request arrived from, and the country Cloudflare places it in. A site your browser reaches the same way sees the same address. If an extension or a PAC file sends some sites through the proxy and others direct, those sites see different ones.
Network. The page sends that address to ipapi.is, which returns the network that announces it and its ASN. The free lookup doesn't say what kind of network that is, so the page guesses from a list of well-known cloud and hosting networks and from the name, and labels the guess as one. Sites run their own lookups to score IP reputation: a datacenter proxy shows up as a hosting company, a residential proxy as a home internet provider.
WebRTC. A page can ask the browser for its public address through a STUN server over UDP, and an HTTP proxy carries web traffic only, so the answer can come from your own connection. The check compares every public address WebRTC reports with the one our API saw, and ignores names ending in .local, which browsers use to keep local addresses private. An address of the other IP version is usually your connection's second address, normal on a dual-stack line, though it still gives you away if your proxy only carries one version. WebRTC leak lists the fixes, browser by browser.
Headers. The page looks for 10 headers that name a proxy or pass on an earlier address: Via, Forwarded, X-Forwarded-For, X-Real-IP, Client-IP, True-Client-IP, X-Client-IP, X-Originating-IP, Proxy-Connection, X-Proxy-ID. Over HTTPS your browser sends the request through an HTTP CONNECT tunnel the proxy can't read, so it can't add any of them. When one appears, something decrypted the traffic on the way, such as a company gateway or a debugging proxy, or your browser or an extension sent it. To see whether a proxy adds headers to plain HTTP, the elite proxy entry shows the test.
Questions
Does this show my real IP address?
It shows the address our server saw. With a proxy on, that is the proxy's exit, and the check can't see past it. WebRTC is the exception: a public address it reports that our server didn't see came from somewhere else on your side, which is often your own connection.
Does a clean result mean my setup is safe from detection?
No. It means the address, the network, WebRTC and the headers look the way the page reports. Sites also read TLS and browser fingerprints, cookies and behaviour, and this page tests none of those.
Why would a proxy add no headers here?
This page and the API are HTTPS. Your browser sends the request through a CONNECT tunnel the proxy can't read, so the proxy has no way to add Via or X-Forwarded-For. A header only arrives when something decrypts the traffic on the way, or when your browser or an extension sends it.
What happens to the result?
We don't store it. The request to our API passes through Cloudflare and our servers like any other request, and ipapi.is and Google receive the requests your browser sends them, under their own terms. Nothing is sent until you press the button.
How does it tell a datacenter address from a home connection?
The page asks ipapi.is without a key, and the keyless answer names the network and its ASN but leaves out the network type and the datacenter, VPN and proxy flags. So the page guesses: from a short list of well-known cloud and hosting networks, then from words in the name. It says when it is guessing, and says it can't tell when the name gives nothing away.
Check a proxy from the terminal
The same check runs from a shell, with no browser in the way. Put your proxy's username, password, host and port in place of USER:PASS@IP:PORT.
The reply is the JSON this page reads: ip is the address the request arrived from, which through a proxy is its exit, and headers lists any of the 10 that arrived. curl has no WebRTC, so a script can't leak that way. The cURL proxy guide covers authentication, SOCKS5 and the errors you will meet.
Terminal
curl -sx http://USER:PASS@IP:PORT https://api.proxyhive.io/tools/echoStart free
Run it again through a ProxyHive IP
Every account starts with 1 GB free. Set one of our proxies in your browser or in the curl line above, then check what sites see.