Guide · 5 min read · 2026-10-06

HTTP, HTTPS and SOCKS5: choosing a protocol

What each proxy protocol does, how HTTPS tunnelling works, and where each choice changes DNS behaviour and client support.

The protocol you speak to the gateway is separate from the protocol you speak to the target. You can reach an HTTPS site through an HTTP proxy, and many do.

HTTP proxy

For plain HTTP, the client sends the full request to the proxy, which forwards it. For HTTPS, the client sends a CONNECT request naming the host and port. The proxy opens a tunnel and the client negotiates TLS through it. The proxy sees the destination host and the volume of traffic, not the content.

what a CONNECT tunnel looks like on the wire
CONNECT example.com:443 HTTP/1.1
Host: example.com:443
Proxy-Authorization: Basic <base64 of USERNAME:PASSWORD>

SOCKS5

SOCKS5 relays TCP connections without interpreting HTTP, so it works for clients that are not HTTP clients at all. It can also carry hostnames to the proxy for resolution, which decides where DNS lookups happen.

DNS: who resolves the hostname

If your machine resolves the hostname before connecting, the lookup leaves from your network and the answer may differ from what the proxy side would see. With curl, the socks5h scheme asks the proxy to resolve; socks5 resolves locally.

curl: local versus proxy-side resolution
curl --proxy socks5://USERNAME:PASSWORD@GATEWAY_HOST:PORT https://example.com/
curl --proxy socks5h://USERNAME:PASSWORD@GATEWAY_HOST:PORT https://example.com/

Choosing

  • Use HTTP or HTTPS for ordinary web collection. Every mainstream HTTP client supports it.
  • Use SOCKS5 for non-HTTP clients, or when you want hostname resolution on the proxy side.
  • Check the product page and your plan for the protocols it lists. Not every product offers every protocol.

More guides

Test it on your own targets.

Create an account, run the measurement harness against your real workload, and read the numbers before you commit to anything.