Proxy checker
Check your connection
Turn the proxy or VPN on first, then press the button. Run it once with and once without and compare: if the address changes, your browser traffic is going through it. Nothing is sent anywhere until you press.
What each check looks at
- Exit IP. The address your request reached our server from. With a proxy on, that is the proxy’s exit; without one, it is your own connection. The country comes from Cloudflare, which sits in front of our server, when it names one.
- Network. Every public address belongs to a network with a number, its ASN. An internet provider’s network looks like a person at home; a hosting network looks like a server. A datacenter proxy is expected to read as hosting. ISP proxies are registered to home internet providers, so they should read as an internet provider even though the server sits in a data centre. The free lookup no longer classes networks itself, so the label is a guess from the network’s number and name, and the page says so.
- WebRTC. Browsers use WebRTC for calls, and to find a route it asks a STUN server which address it sees, over UDP and outside the proxy that carries your pages. The check listens for about three seconds and compares what comes back with the exit IP. A different public address of the same IP version is a WebRTC leak. One of the other version is usually your own connection’s second address, normal on a dual-stack line, though it still gives you away if the proxy only carries one version.
- Proxy headers. A proxy relaying plain HTTP often adds
ViaorX-Forwarded-For, naming itself or you. This check runs over HTTPS, where a proxy only passes encrypted bytes through and cannot add anything. A header here means a proxy that decrypts your traffic, or one your own client sent. - Not checked: DNS. Lookups that skip the proxy are a DNS leak, and spotting one takes a DNS server of our own. The glossary entry says how to test for it.
Proxy set for a few sites only? The check talks to api.proxymonkey.io, so add that host to the rules in your PAC file, or the check goes direct and shows your own address.
Check a proxy from a terminal
The same server answers curl. Put your proxy’s login, IP and port in place of the capitals:
curl -sx http://USER:PASS@IP:PORT https://api.proxymonkey.io/tools/echoThe reply is JSON: ip is the address a site sees through that proxy, and revealing lists any proxy headers. Add | jq to the end to pretty-print it, or | jq -r .ip for the address alone. The network type is looked up by this page in your browser, so the terminal reply does not carry it.
Checking a whole list, with speed and a pass or fail per proxy? Build a proxy checker in Python walks through the script. Testing proxies from a free list first? What free proxy lists actually cost you explains why most fail before they reach this page.
What gets sent where
- Our server, api.proxymonkey.io. Sees your IP address and request headers, because that is the check, and sends back your address, a short list of proxy-revealing headers and your user agent. We don’t store the result. The server keeps ordinary request logs, as any web server does. Cookies are not sent.
- ipapi.is. Your browser asks this third-party service about the address from the first step, to name the network. It sees your address doing so.
- Google’s STUN server. The WebRTC check sends one request to stun.l.google.com, which sees the address it arrives from.
Nothing goes to any of the three until you press the button.
Questions
Can this tell me whether my proxy works?
Not on its own, because we never see your real address to compare against. Run it once with the proxy off and once with it on. If the address and network change, your browser traffic is going through the proxy. If WebRTC still shows the first address, that is the leak to fix.
Why does my datacenter proxy show up as hosting?
Because it is one. Datacenter IPs sit on hosting networks, and the IP databases sites pay for class them that way; that is not a fault. The free lookup this page uses does not class networks, so the label here is a guess from the network’s number and name, and says so. If a site turns hosting networks away, the fix is an IP on a consumer ISP network: an ISP proxy or a residential one.
My proxy adds headers. Why does the checker show none?
This page talks HTTPS. Your browser opens an encrypted tunnel through the proxy with CONNECT, and the proxy passes along bytes it cannot read or change. Headers only show up when something in the middle decrypts the traffic, or when your own client sends them.
Do you keep my IP address?
We don’t store the result. Our server at api.proxymonkey.io keeps ordinary request logs, as any web server does. ipapi.is and Google’s STUN server see your address when the page asks them, and that is everything that leaves your browser.
Is WebRTC the only way a browser gives you away?
No. DNS lookups can also leave outside the proxy, and this page cannot see them: catching one takes a DNS server of our own watching which resolver asks. The glossary entry on DNS leaks says how to test for one.
Checker says something odd?
Paste the result in Discord and say what you expected. Someone will tell you whether it is the proxy, the browser or us.
Join the Discord4,200+monkeys in the Discord
Help from humans
Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.
A status bot that tells on us
Pool health, incidents and maintenance posted automatically. Including the bad days.
Deals and free traffic
Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.