How do you tell whether an error came from the proxy or the website?
Look at where the status code appears. For an HTTPS site, your client first asks the proxy to open a tunnel with an HTTP CONNECT request. The proxy answers that request itself: 200 if it opened the tunnel, or an error such as 407, 403, 502 or 503 if it did not. Everything after a 200 is the website talking through the tunnel.
curl -v prints both answers, so it is the quickest way to see which side refused:
curl -v -x http://YOUR_HOST:8080 -U "YOUR_USERNAME:YOUR_PASSWORD" https://example.com/ -o /dev/null> CONNECT example.com:443 HTTP/1.1
< HTTP/1.1 407 Proxy Authentication Required
< X-Proxy-Reason: Wrong proxy password. Check the credentials on your service page.
* CONNECT tunnel failed, response 407> CONNECT example.com:443 HTTP/1.1
< HTTP/1.1 200 Connection established
...
> GET / HTTP/2
< HTTP/2 429
< retry-after: 30A plain http:// site works differently: the proxy forwards the request itself, so you read one response. The TrueProxies gateway puts its own reasons in the X-Proxy-Reason header in both cases.
Proxy error codes at a glance
| Symptom | Comes from | Likely cause | Fix |
|---|---|---|---|
| 407 with “Wrong proxy password…” | Proxy | The password does not match the service | Copy the proxy password from the Username and password tab; percent-encode special characters in URL-form credentials |
| 407 with “Username not recognised…” | Proxy | A typo in the username, or the service has ended | Copy the username from your service page and check that the service is active |
| 407 with “The targeting options in your username are not valid for this service…” | Proxy | A misspelled, unsupported or repeated option, such as country-usa | Use two-letter country codes, only the options your product supports, and each option once |
| 407 with “No credentials sent, and this address is not on the service's trusted IP list.” | Proxy | No username and password, from an address that is not a trusted IP | Send credentials, or add your public IP as a trusted IP |
| 407 naming a limit or the service's state | Proxy | Too many open or new connections, a suspended or expired service, used traffic, or a closed trial | Do what the sentence says: lower concurrency, renew, add traffic or contact support |
| 407 with no reason | Proxy | A short lockout after repeated failed logins from your address | Stop retrying, fix the credentials, and try again after about a minute |
| 403 after the tunnel opens | Website | The site refused this request under its own rules | Check the site's terms and robots.txt, slow down, and compare with a request from your own connection |
| 403 as the answer to CONNECT | Proxy | The destination is on the network's blocked list | Use a different destination, or contact support if you think it is wrong |
| 429 Too Many Requests | Website | More requests than the site allows in a period | Wait for the Retry-After time, then lower request rate and concurrency |
| 502 with “Datacenter IPv6 proxies reach IPv6 destinations only…” | Proxy | A Datacenter IPv6 service asked for a site with no IPv6 address | Use Residential IPv4 for that site, and check other targets with the IPv6 test |
| 502 or 503 as the answer to CONNECT, no reason | Proxy | The proxy could not open a connection: the site refused or did not answer, no exit was free for your targeting, or the port is closed | Retry, check the host and port, and widen targeting if you set one |
| 502, 503 or 504 after the tunnel opens | Website or its CDN | The site's own servers failed | Retry later with backoff; the proxy is working |
| Timeout | Either side | A slow or silent site, an exit that went away, DNS, or a client timeout set too short | Retry once, raise the client timeout, and test the route with Proxy Checker |
| Slow transfers | Either side | The plan speed ceiling, a slow site, distance to the exit, or how many connections you use | Compare measured download speed with plan speed, and test another site |
| SOCKS5 authentication failure | Proxy | SOCKS5 has no field for a reason | Send the same username once over HTTP with curl -v and read X-Proxy-Reason |
What does a 407 from TrueProxies mean?
407 Proxy Authentication Required is the proxy's own refusal (RFC 9110, section 15.5.8). A bare 407 reads as “wrong password” whatever the cause, so the TrueProxies gateway adds a sentence that says which check failed. It sends the sentence in the response body and in the X-Proxy-Reason header.
The header matters because browsers and most HTTPS libraries never show you the body of a failed CONNECT. Log the header, or run the request once with curl -v. These are the sentences the gateway sends:
- “Wrong proxy password. Check the credentials on your service page.”
- “Username not recognised. Check the username on your service page.”
- “Username not recognised, or the service it belongs to has ended. Check your service page.”
- “The targeting options in your username are not valid for this service. Check spelling, and do not repeat an option.”
- “No credentials sent, and this address is not on the service's trusted IP list.”
- “This service is at its maximum number of open connections.” and “Too many new connections per second for this service's limit.”
- “This service is suspended. Contact support to resolve it.”, “This service has reached its expiry date. Renew it to continue.” and “This service has used its traffic allowance. Add traffic to continue.”
- “Your trial has closed. Buy a paid plan to continue.”
- “The proxy is at capacity right now. Try again in a moment.”
A targeting error is answered before any exit is chosen, so it uses no traffic. For example, country-usa is refused because country codes have two letters (country-us), and -country-us-country-gb is refused because an option appears twice. The How to connect guide lists every option each product accepts.
If a 407 carries no sentence at all, your address has most likely been locked out for about a minute after repeated failed logins. Stop retrying, fix the credentials, then try again.
Two setup details also produce 407s. A password with special characters must be percent-encoded when it is written inside a proxy URL (@ becomes %40). And a trusted IP only admits connections from the public address you added; see trusted IPs.
Why do 403 and 429 come from the website, not the proxy?
Once the tunnel is open, the status codes you see are the website's. A 403 Forbidden means the site understood the request and refused it (RFC 9110). A 429 Too Many Requests means you sent more requests than the site allows in a period, and the site may add a Retry-After header that says when to try again (RFC 6585).
A different exit address does not make a refused request permitted. Treat both codes as the site's instructions: honor Retry-After, lower concurrency, space out requests, and check the site's terms and robots.txt. Under the TrueProxies acceptable use policy, you are responsible for following the terms of every site you reach through the service.
One exception: a 403 returned as the answer to CONNECT, before any TLS, comes from the proxy. On TrueProxies that means the destination is on the network's blocked list.
What do 502, 503 and 504 mean through a proxy?
These are gateway errors: something between you and the site could not get a usable answer (RFC 9110). Where the code appears tells you which side failed.
- Answer to CONNECT, with a reason. On TrueProxies, a 502 whose
X-Proxy-Reasonreads “Datacenter IPv6 proxies reach IPv6 destinations only. This destination has no IPv6 address.” means the site has no IPv6 address. Use Residential IPv4 for it, and check your other targets for IPv6. - Answer to CONNECT, no reason. The gateway could not open a connection to that host and port. The site may have refused or not answered, a country you targeted may have no exit free at that moment, or the port may be closed. On the free trial only ports 80 and 443 are open, and outgoing mail ports are closed on every service.
- After the tunnel opened. The website or its CDN returned the error. The proxy did its job; retry later with backoff.
A 504 Gateway Timeout comes from a gateway that waited too long for the server behind it. After the tunnel opens, that gateway belongs to the website.
Why does a proxy connection time out?
A timeout means no answer arrived before your client gave up. Find the stage first: connecting to the proxy, the proxy opening the tunnel, the TLS handshake with the site, or waiting for the site's first byte.
- Connecting to the proxy. Check the connection host and port on your service page, and that your network allows outgoing connections to that port.
- Opening the tunnel. The site is slow to accept connections, or a residential exit went away during setup. Retry once. If one site times out while others work, the site is the cause.
- TLS or first byte. The site is slow to respond. Raise your client's read timeout for slow pages instead of retrying at once.
- DNS. With SOCKS5, let the proxy resolve hostnames (
socks5h://) so a local resolver problem does not look like a proxy timeout.
The Proxy Checker separates a proxy problem from a site problem: it reports whether the proxy route works and, separately, whether a selected target answered, each within eight seconds. Its error code guide explains each stage. On your service page, Usage history lists recorded errors by type, such as Connection setup timeout, Read timeout and DNS error.
Why is my proxy slow?
A slow proxy is usually held back by one of four things: the plan speed, the website, the distance to the exit, or how your client uses connections.
- Plan speed. Residential IPv4 Unlimited plans run from 10 Mbps to 1 Gbps, and Datacenter IPv6 plans from 25 to 400 Mbps. Plan speed is the ceiling for the service at its peak, not what each connection or each site will deliver. Residential IPv4 GB-based is charged by traffic, not by plan speed.
- The website. A site can limit how fast it serves one client. If one site is slow and others are not, the site is the limit.
- Distance and exit type. Setup takes longer as the distance between you, the exit and the site grows. Residential exits run on household connections, so their speed varies from exit to exit.
- Connections. A single connection may not fill a fast plan. Opening many at once can reach the service's open-connection limit and draw a 407.
Measure before you change plans. Compare Download speed in Live traffic on your service page with your plan speed: if you are well below it, a faster plan will not help. The latency vs speed guide explains why a fast first response and a fast download are different measurements, and sizing your plan speed shows how to measure a real batch.
How do you troubleshoot a SOCKS5 proxy error?
SOCKS5 cannot tell you why it refused. Its username and password step returns one status byte, success or failure, with no text (RFC 1929), and a refused destination comes back as a short reply code such as network unreachable (RFC 1928).
To see the reason, send the same username once over HTTP. The connection host serves HTTP on port 8080 and SOCKS5 on port 1080 with the same credentials, so the HTTP answer names the problem:
# Same username and password as your SOCKS5 client, sent over HTTP
curl -v -x http://YOUR_HOST:8080 -U "YOUR_USERNAME-country-us:YOUR_PASSWORD" https://example.com/ -o /dev/nullRead the X-Proxy-Reason line, fix the username, then switch back to SOCKS5. With SOCKS5, prefer socks5h:// (or --socks5-hostname in curl) so hostnames are resolved at the proxy.
What should you send to support?
If these steps do not explain an error, contact support with:
- The time of the error in UTC, and the product: Residential IPv4 Unlimited, Residential IPv4 GB-based or Datacenter IPv6
- The protocol and port: HTTP 8080, HTTPS 8443 or SOCKS5 1080
- The target hostname and the status code you saw
- The exact
X-Proxy-Reasontext, if there was one - Your username. Never send your proxy password.