Guide · 6 min read

How to set a proxy on Windows 11: settings, PowerShell and per-app

Set a proxy on Windows 11 in Settings, from PowerShell and netsh, and per app with environment variables, plus where Windows keeps the password.

Windows has not one proxy setting but three: the one in Settings that your browser uses, a separate one for Windows services, and the environment variables that command-line tools read. Setting the first and expecting the other two to follow is the most common reason a proxy “does nothing”. This guide covers all three, with the menu names as they appear in Windows 11, checked in September 2026.

How to set a proxy on Windows 11

Short answer: Settings → Network & internet → Proxy, then under Manual proxy setup, click Set up next to Use a proxy server. In full:

  1. Open Settings and select Network & internet, then Proxy.
  2. Under Manual proxy setup, next to Use a proxy server, select Set up.
  3. In the Edit proxy server dialog, turn on Use a proxy server.
  4. Enter the IP from your dashboard in Proxy IP address and its port in Port.
  5. Leave Don’t use the proxy server for local (intranet) addresses ticked, as Microsoft recommends. It keeps your router and printer off the proxy.
  6. Select Save.

The same page has Automatically detect settings and Use setup script. The first is for office networks that announce a proxy; the second takes the address of a PAC file. If you typed a proxy in manually, leave both off, or Windows may pick something other than what you typed.

Exceptions: sites that skip the proxy

The box under the address takes the endings of sites that should go direct, separated by semicolons. The * is a wildcard:

*.example.com; *.example.org; 192.168.*

Every site not on that list goes through the proxy, from every app that follows this setting. That is the catch with a system-wide proxy. Browsers, the mail client and most desktop apps use it, and on a proxy billed by the gigabyte, a large download you forgot was running is an expensive surprise. If you only want a browser proxied, the Chrome and Firefox guide shows how to keep it to one window.

Where Windows keeps the proxy username and password

Mostly, it doesn’t. The Edit proxy server dialog has no username or password field, so Windows passes the proxy on without any. When the proxy answers with 407, each app deals with it on its own: Edge and Chrome show a sign-in box and remember the answer until you close them, some apps offer to save it, and many simply fail with a network error.

When a Windows dialog does offer to remember a proxy password, it normally lands in Credential Manager (search for it in the Start menu, then Windows Credentials). If a wrong password keeps being sent, look there for an entry naming the proxy IP and remove it.

For a whole-machine proxy, the cleaner answer is to need no password. Every ProxyMonkey line supports an IP allowlist: add your public IP in the dashboard, and every app on the machine gets through without a prompt. It holds only while your IP stays the same, and anyone else behind that IP can use the proxy too.

netsh winhttp: the proxy Windows services use

Windows has two built-in web stacks. Apps you run yourself mostly use WinINet, which follows the Settings page. Services and background processes use WinHTTP, which has its own proxy setting and ignores the Settings page completely. If Windows Update or an agent that runs as a service is not using your proxy, this is why.

Set it from a terminal opened as administrator:

netsh winhttp show proxy
netsh winhttp set proxy proxy-server="IP:PORT" bypass-list="*.example.com;<local>"

Or copy what you set in Settings, and later undo it:

netsh winhttp import proxy source=ie
netsh winhttp reset proxy

The name source=ie is a leftover from Internet Explorer; it reads the same per-user setting the Settings page writes. WinHTTP takes no password either, so for services an IP allowlist is the only option that works unattended.

One more thing Microsoft’s own comparison of the two stacks makes clear: neither WinINet nor WinHTTP supports SOCKS5. The Windows proxy settings are for HTTP proxies. For SOCKS5, set it inside the app that needs it.

PowerShell proxy: environment variables for command-line tools

Command-line tools such as curl.exe, git, pip and most language package managers do not look at the Settings page. They read HTTP_PROXY and HTTPS_PROXY. Environment variable names are not case-sensitive on Windows, so the upper- and lower-case spellings other guides argue about are the same variable here.

For the current PowerShell window only:

$env:HTTP_PROXY  = "http://USER:PASS@IP:PORT"
$env:HTTPS_PROXY = "http://USER:PASS@IP:PORT"
$env:NO_PROXY    = "localhost,127.0.0.1"

Note the http:// in HTTPS_PROXY. It is the protocol for reaching the proxy, not the site, and writing https:// there is a common cause of TLS errors. The same in Command Prompt is set HTTPS_PROXY=http://USER:PASS@IP:PORT.

To make it stick for new windows, use setx:

setx HTTPS_PROXY "http://USER:PASS@IP:PORT"
setx HTTP_PROXY "http://USER:PASS@IP:PORT"

setx writes the value to your user environment for windows you open from now on; the window you typed it in does not change. It also means your password now sits in plain text where any program you run can read it. That is one more reason to prefer an IP allowlist on a machine you share. To remove it, delete the variable under Edit environment variables for your account in the Start menu.

Which apps ignore the Windows proxy settings

  • Follow Settings: Edge, Chrome and most desktop apps built on Windows’ own networking.
  • Firefox: follows the system by default, but has its own proxy settings that override it.
  • Windows services: WinHTTP, via netsh, as above.
  • curl.exe, git and most CLI tools: environment variables only.
  • Python: requests reads the environment variables first and falls back to the Settings page if there are none. It never gets a password from Settings, though, so with a password-protected proxy you still need the variables or the proxy in code.
  • Node.js: ignores the system settings. Whether it reads the variables depends on the library, so set the proxy in code.
  • Games, many VPN clients and anything using UDP: not through an HTTP proxy at all.

Check your exit IP with curl.exe

In PowerShell, type curl.exe rather than curl. In Windows PowerShell, curl is a shortcut for a different command with different flags. Test the proxy directly first, so you know the details are right:

curl.exe -x http://IP:PORT --proxy-user USER:PASS https://httpbin.org/ip

The origin in the reply should be your proxy’s IP. With the environment variables set, a plain curl.exe https://httpbin.org/ip should print the same. To check the Settings page proxy instead, open https://httpbin.org/ip in Edge; curl does not read that setting, so it cannot test it. More flags are on the curl setup page.

Windows proxy not working? Common fixes

The sign-in box keeps coming back

The proxy is rejecting the credentials, or getting none. Copy them fresh from the dashboard, clear any saved entry in Credential Manager, and check that the password has no characters that need escaping in a URL. The 407 Proxy Authentication Required page goes through each cause.

No internet at all after turning the proxy on

Windows could not reach the proxy, so everything that follows the setting fails. Usually the IP or port is mistyped, or the order behind it has ended. Test with the curl.exe -x line above; if that fails too, the connection refused guide is next. Turn Use a proxy server off to get back online while you look.

The settings are greyed out or change back

On a work or school PC, a policy sets the proxy and wins. At home, look for a VPN client or other proxy software that rewrites the setting each time it starts.

Which proxy to use for a whole machine

A system-wide proxy wants one address that does not move. A static ISP proxy or datacenter proxy gives you exactly that. Rotating residential gives a new exit on every new connection, and Windows apps open connections constantly, so logins break and sites ask you to prove who you are; if you need residential, turn on a sticky session in your dashboard first.

Setting up a Mac as well? The macOS proxy settings guide covers the same ground there. For per-site rules in a browser instead of a whole-machine proxy, see the FoxyProxy setup guide.

Try it while you read

Top-ups start at $5.

One shared datacenter IP for 30 days is $2.10. A single gigabyte of residential is $5.50. The balance never expires.

Published

Filed under

Found a mistake? Tell us in Discord and we will fix the post.

The community layer

Stuck halfway through?

Paste the error in Discord. Someone has hit it before and the answer is usually one message long.

Join the Discord

4,200+monkeys in the Discord

  • Help from humans

    Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.

  • A status bot that tells on us

    Pool health, incidents and maintenance posted automatically. Including the bad days.

  • Deals and free traffic

    Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.

Join the Discord4,200+ monkeys, free to lurk