Proxy error · ECONNREFUSED

Connection refused

Connection refused is the quickest failure there is. A machine answered your connection attempt with a flat no, before HTTP, TLS or credentials came into it. The question is which machine, and with a proxy set the answer is nearly always the one in your proxy settings.
Whose fault is it?

If your tool says refused, look at the proxy address you configured. If the site had refused, you would be reading a 502.

Usually from
The proxy address in your config
Try first
Check host and port against the dashboard, then test in curl
With a proxy in the path

What a refused connection means through a proxy

At the TCP level, refused means a host was reachable and nothing was listening on that port, or a firewall rejected the connection outright. A dropped connection looks different: it hangs, then times out.

With a proxy set, your client only ever opens a connection to the proxy. So a refused error from your client was refused on that leg.

When the site refuses the proxy’s outgoing connection, you do not see a refused error. The proxy turns it into a status on the CONNECT, typically 502, and your tool reports a tunnel failure.

The key question

Your credentials, the proxy, or the target?

If your tool says refused, look at the proxy address you configured. If the site had refused, you would be reading a 502.

  • Your credentials

    Not the cause. Credentials are checked after a connection is accepted.

  • The proxy

    The proxy address your config points at: a mistyped host or port, or an old address copied from an earlier order. The dashboard lists the current ones.

  • The target site

    Only indirectly. A site refusing the proxy shows up as a 502 on the CONNECT.

How to tell

  • Refused within milliseconds: something answered and said no. A long wait followed by an error is a timeout.
  • nc -vz HOST PORT against the proxy address shows whether anything is listening there at all.
  • curl prints Failed to connect to with the proxy host and port, and exits with code 7.
  • Python Requests raises ProxyError with Connection refused in it; Node puts ECONNREFUSED on err.cause; Chromium says net::ERR_PROXY_CONNECTION_FAILED.
Cheapest first

Fixes, in the order to try them

  1. Compare host and port with the dashboard

    Character by character. The residential gateway and each ISP or datacenter IP have their own host and port, and the dashboard lists them for every order.

    Costs nothing
  2. Check for an empty variable

    A proxy URL assembled from environment variables that are not set can end up pointing at your own machine, which refuses. Print the host and port your code is using.

    Costs nothing
  3. Test from the same machine with curl

    If curl connects and your program does not, the problem is in the program’s config. If curl is refused too, it is the address or your network.

    Costs nothing
  4. Check the order is still active

    An ISP or datacenter address is yours for the term you picked. Look at the order in the dashboard before debugging further.

    Costs nothing
  5. Check outbound firewalls

    Company networks and some hosting providers restrict outbound ports. A firewall that rejects shows as refused; one that drops shows as a timeout.

    Costs some time
Per tool

See the real status and headers

Each sample prints the host and port that were refused, which is usually enough to spot the mistake.

curl
terminal
# is anything listening at the proxy address?
nc -vz resi.proxymonkey.io 8000
nc -vz IP PORT          # an ISP or datacenter IP from your order

# which host and port curl tried, and what happened
curl -sv -o /dev/null -x http://USER:[email protected]:8000 https://httpbin.org/ip 2>&1 | head -n 5

# curl: (7) Failed to connect to ... port ...: Connection refused
Python Requests
where.py
import os
from urllib.parse import urlsplit

import requests

proxy = os.environ.get("PROXY_URL", "")
parts = urlsplit(proxy)
print("proxy host:", parts.hostname, "port:", parts.port)

try:
    requests.get("https://httpbin.org/ip", proxies={"http": proxy, "https": proxy}, timeout=15)
except requests.exceptions.ProxyError as err:
    print(err)

Set PROXY_URL to http://USER:PASS@IP:PORT for a rented IP, or to the residential gateway.

Scrapy
in the spider
from urllib.parse import urlsplit

from twisted.internet.error import ConnectionRefusedError

def start_requests(self):
    for url in self.start_urls:
        yield scrapy.Request(url, errback=self.on_error)

def on_error(self, failure):
    if failure.check(ConnectionRefusedError):
        proxy = urlsplit(failure.request.meta.get("proxy", ""))
        self.logger.error("refused at %s:%s", proxy.hostname, proxy.port)

The log line prints host and port only, so the password stays out of your logs.

Playwright
where.py
from playwright.sync_api import Error, sync_playwright

PROXY = {"server": "http://resi.proxymonkey.io:8000", "username": "USER", "password": "PASS"}

with sync_playwright() as p:
    browser = p.chromium.launch(proxy=PROXY)
    page = browser.new_page()
    try:
        page.goto("https://httpbin.org/ip")
    except Error as err:
        print(err.message.splitlines()[0])
    browser.close()

# net::ERR_PROXY_CONNECTION_FAILED    nothing accepted the connection at the proxy address
# net::ERR_TUNNEL_CONNECTION_FAILED   the proxy answered, but the CONNECT failed
Node.js
where.mjs
import { fetch, ProxyAgent } from "undici";

const dispatcher = new ProxyAgent("http://USER:[email protected]:8000");

try {
  await fetch("https://httpbin.org/ip", { dispatcher });
} catch (err) {
  const { code, address, port } = err.cause ?? {};
  console.error(code, address, port);
}

// ECONNREFUSED 203.0.113.7 8000

The samples use the residential gateway, resi.proxymonkey.io:8000. For an ISP or datacenter IP, use USER:PASS@IP:PORT for the address you rented. Your dashboard lists the host and port for every order, and where it differs from this page, the dashboard is right.

Before you buy anything

Will a different proxy line fix it?

When switching helps

No line fixes a refused connection by itself. A new order helps only when the one you point at has ended, and renewing that one works as well.

When it will not

A typo, an empty variable or a firewall follows you to every line. Fix the address first.

The meter

Is a failed request billed?

We bill for request bytes and response bytes, including headers and protocol overhead on the tunnelled connection. Connections that fail before transferring data are not billed. Retries that you initiate are billed and appear as separate entries in your usage log.

From the metering section of our terms of service.

The terms say connections that fail before transferring data are not billed. A refused connection is turned away before anything transfers. Retries you initiate are billed as separate entries once they do move data.

Residential is billed per GB of that traffic. ISP and datacenter addresses are charged per IP for their term, and where a plan includes a traffic allowance, traffic past it is billed per GB under the same rule. The usage log in your dashboard has one row per request with bytes in, bytes out and cost, so you can look up the failed request yourself.

ECONNREFUSED, asked often

Questions people ask about a refused connection

Is connection refused the website blocking me?

Not while a proxy is set. Your client only connects to the proxy, so a refused error is about the proxy address. A site refusing the proxy produces a 502 on the tunnel.

What is the difference between refused and timed out?

Refused is an instant no: a host answered and nothing accepted the connection. Timed out is silence: the packets went nowhere, or something dropped them. Refused points at the address; a timeout points at the network or a slow leg.

My ISP proxy worked yesterday and is refused today. Why?

Check the order in the dashboard first, since an address is yours for the term you bought. If the order is active and curl from your machine is refused too, post the curl output in the Discord with the password removed.

Does SOCKS5 give the same error?

On the leg to the proxy, yes: refused is refused. Past that, a SOCKS5 proxy reports a target that refused through its own reply codes, which curl shows as a SOCKS error instead of a 502.

The community layer

Still stuck on a refused connection?

Paste your error in the Discord: the full message plus the command or the few lines that set up the proxy, with the password taken out. Someone there has seen it before.

Join the Discord

4,200+monkeys in the Discord

  • Help from humans

    Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.

  • A status bot that tells on us

    Pool health, incidents and maintenance posted automatically. Including the bad days.

  • Deals and free traffic

    Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.

Join the Discord4,200+ monkeys, free to lurk