Proxy errors

Your proxy threw an error. Whose is it?

Every proxy error comes from one of three places: your credentials, the proxy, or the site you are scraping. Work out which before you change anything, because the fixes have nothing in common.
One command settles most of them
terminal
curl -s -o /dev/null -x http://USER:[email protected]:8000 \
     -w 'proxy: %{http_connect}  site: %{http_code}\n' \
     https://example.com/

Over HTTPS the proxy only speaks when it answers the CONNECT. The first number is the proxy; the second is the site. Your dashboard lists the host and port for every order, and it wins over this page.

Quick triage

The error, where it usually comes from, and what to try first

Common proxy errors, their likely source, and the first thing to try
ErrorUsually fromTry first
407 407 Proxy Authentication RequiredThe proxy, about your credentialsCopy USER:PASS fresh from the dashboard and retry in curl
403 403 ForbiddenThe target siteLoad the same URL without the proxy and compare
429 429 Too Many RequestsThe target, about your request rateRead Retry-After and wait that long
502 502 Bad GatewayEither: the proxy path or the site’s load balancerCheck whether it came on the CONNECT or inside the tunnel
503 503 Service UnavailableUsually the target; sometimes the proxy pathRead the body: outage page, challenge page, or tunnel error
TIMEOUT Connection timeoutAny leg; residential exits are the usual slow oneSet separate connect and read timeouts and see which fires
TLS SSL certificate errorsYour client config, or the site’s certificateWrite the proxy URL with http:// and update your CA bundle
ECONNREFUSED Connection refusedThe proxy address in your configCheck host and port against the dashboard, then test in curl
The rule behind the table

Over HTTPS, the proxy only talks during CONNECT.

To reach an HTTPS site, your client asks the proxy to open a tunnel with CONNECT host:443. The proxy answers that once. After it says 200, TLS runs end to end between you and the site, and the proxy passes encrypted bytes it cannot read or change.

So a status that comes back as the answer to CONNECT is the proxy’s, and your tool usually reports it as a proxy or tunnel exception. A status you read from an ordinary response is the site’s. A 407 is always the first kind. A 403 or 429 read from a response is always the second. A 502 or 503 can be either, and the curl command above tells you which.

Further reading

Stop the errors before they start

The long version of the three errors people hit most is in the guide to 407, 403 and 429. Each setup guide lists the exact messages its tool prints, and not getting blocked covers pacing and headers in depth.

The community layer

Error not on the list?

Paste it in the Discord, with the command that caused it and the password taken out. Someone there has probably seen it already.

Join the Discord

4,200+monkeys in the Discord

  • Help from humans

    Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.

  • A status bot that tells on us

    Pool health, incidents and maintenance posted automatically. Including the bad days.

  • Deals and free traffic

    Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.

Join the Discord4,200+ monkeys, free to lurk