How does a SOCKS5 proxy work?
SOCKS5 is defined in RFC 1928. A connection goes through four steps:
- Greeting. Your application connects to the proxy and lists the login methods it supports.
- Authentication. The proxy picks a method, for example username and password (RFC 1929), and checks your credentials.
- Connect request. Your application sends the destination as an IP address or a host name and port.
- Relay. The proxy connects to the destination and passes bytes in both directions until either side closes the connection.
The proxy never reads or rewrites what passes through, which is why SOCKS5 works with almost any protocol that runs over TCP.
SOCKS5 vs HTTP proxies
| SOCKS5 proxy | HTTP proxy | |
|---|---|---|
| Traffic it carries | Any TCP protocol, and UDP where enabled | HTTP, plus HTTPS through a CONNECT tunnel |
| Reads your traffic | No | Can read plain HTTP; HTTPS stays encrypted |
| Changes headers | Never | May add headers to plain HTTP requests |
| DNS lookups | On your machine, or at the proxy with socks5h | At the proxy |
| Typical use | Non-web traffic and tools with SOCKS support | Web scraping, browsers and HTTP libraries |
For websites, both work. Most scraping libraries support HTTP proxies first, so use HTTP unless you need what only SOCKS5 offers.
SOCKS4 vs SOCKS5
SOCKS4 handles TCP only and has no password login. SOCKS4a added host names. SOCKS5 adds username and password authentication, UDP, IPv6 and host names, so it has replaced SOCKS4 almost everywhere.
socks5 vs socks5h
Both schemes use the same protocol. The difference is where the host name is resolved:
socks5://: your machine looks up the IP address, then asks the proxy to connect to it. The DNS query leaves from your network.socks5h://: your machine sends the host name, and the proxy resolves it. The lookup happens in the proxy's location.
Use socks5h when you want location-accurate DNS and no lookups from your own network.
When should you use SOCKS5?
- Non-HTTP traffic, such as custom TCP protocols, on the ports the network allows.
- Applications with built-in SOCKS support but no HTTP proxy setting.
- Clean tunnelling, when you do not want any proxy to touch HTTP headers.
How to use SOCKS5 with FuseProxy
Every FuseProxy plan supports HTTP, HTTPS, SOCKS5. Point your client at the SOCKS5 port with your credentials:
curl -x "socks5h://USERNAME:PASSWORD@HOST:PORT" https://api.ipify.orgProtocols has Python and Node.js examples and the port for each protocol. SOCKS5 proxies covers plans and pricing.