Skip to content
By TrueProxies10 min read

Proxy errors explained: 407, 403, 429, 502, timeouts and slow connections

A 407 comes from the proxy: it refused the connection, for example over the password, username or targeting options. A 403 or 429 that arrives after the tunnel opens comes from the website. A 502 or 503 from the proxy means it could not open the connection. On TrueProxies, a 407 usually names its reason in the X-Proxy-Reason header.

How do you tell whether an error came from the proxy or the website?

Look at where the status code appears. For an HTTPS site, your client first asks the proxy to open a tunnel with an HTTP CONNECT request. The proxy answers that request itself: 200 if it opened the tunnel, or an error such as 407, 403, 502 or 503 if it did not. Everything after a 200 is the website talking through the tunnel.

curl -v prints both answers, so it is the quickest way to see which side refused:

Show the proxy's answer and the website's answerbash
curl -v -x http://YOUR_HOST:8080 -U "YOUR_USERNAME:YOUR_PASSWORD" https://example.com/ -o /dev/null
Excerpt: the proxy refused the tunneltext
> CONNECT example.com:443 HTTP/1.1
< HTTP/1.1 407 Proxy Authentication Required
< X-Proxy-Reason: Wrong proxy password. Check the credentials on your service page.
* CONNECT tunnel failed, response 407
Excerpt: the tunnel opened and the website answered 429text
> CONNECT example.com:443 HTTP/1.1
< HTTP/1.1 200 Connection established
...
> GET / HTTP/2
< HTTP/2 429
< retry-after: 30

A plain http:// site works differently: the proxy forwards the request itself, so you read one response. The TrueProxies gateway puts its own reasons in the X-Proxy-Reason header in both cases.

Proxy error codes at a glance

SymptomComes fromLikely causeFix
407 with “Wrong proxy password…”ProxyThe password does not match the serviceCopy the proxy password from the Username and password tab; percent-encode special characters in URL-form credentials
407 with “Username not recognised…”ProxyA typo in the username, or the service has endedCopy the username from your service page and check that the service is active
407 with “The targeting options in your username are not valid for this service…”ProxyA misspelled, unsupported or repeated option, such as country-usaUse two-letter country codes, only the options your product supports, and each option once
407 with “No credentials sent, and this address is not on the service's trusted IP list.”ProxyNo username and password, from an address that is not a trusted IPSend credentials, or add your public IP as a trusted IP
407 naming a limit or the service's stateProxyToo many open or new connections, a suspended or expired service, used traffic, or a closed trialDo what the sentence says: lower concurrency, renew, add traffic or contact support
407 with no reasonProxyA short lockout after repeated failed logins from your addressStop retrying, fix the credentials, and try again after about a minute
403 after the tunnel opensWebsiteThe site refused this request under its own rulesCheck the site's terms and robots.txt, slow down, and compare with a request from your own connection
403 as the answer to CONNECTProxyThe destination is on the network's blocked listUse a different destination, or contact support if you think it is wrong
429 Too Many RequestsWebsiteMore requests than the site allows in a periodWait for the Retry-After time, then lower request rate and concurrency
502 with “Datacenter IPv6 proxies reach IPv6 destinations only…”ProxyA Datacenter IPv6 service asked for a site with no IPv6 addressUse Residential IPv4 for that site, and check other targets with the IPv6 test
502 or 503 as the answer to CONNECT, no reasonProxyThe proxy could not open a connection: the site refused or did not answer, no exit was free for your targeting, or the port is closedRetry, check the host and port, and widen targeting if you set one
502, 503 or 504 after the tunnel opensWebsite or its CDNThe site's own servers failedRetry later with backoff; the proxy is working
TimeoutEither sideA slow or silent site, an exit that went away, DNS, or a client timeout set too shortRetry once, raise the client timeout, and test the route with Proxy Checker
Slow transfersEither sideThe plan speed ceiling, a slow site, distance to the exit, or how many connections you useCompare measured download speed with plan speed, and test another site
SOCKS5 authentication failureProxySOCKS5 has no field for a reasonSend the same username once over HTTP with curl -v and read X-Proxy-Reason

What does a 407 from TrueProxies mean?

407 Proxy Authentication Required is the proxy's own refusal (RFC 9110, section 15.5.8). A bare 407 reads as “wrong password” whatever the cause, so the TrueProxies gateway adds a sentence that says which check failed. It sends the sentence in the response body and in the X-Proxy-Reason header.

The header matters because browsers and most HTTPS libraries never show you the body of a failed CONNECT. Log the header, or run the request once with curl -v. These are the sentences the gateway sends:

  • “Wrong proxy password. Check the credentials on your service page.”
  • “Username not recognised. Check the username on your service page.”
  • “Username not recognised, or the service it belongs to has ended. Check your service page.”
  • “The targeting options in your username are not valid for this service. Check spelling, and do not repeat an option.”
  • “No credentials sent, and this address is not on the service's trusted IP list.”
  • “This service is at its maximum number of open connections.” and “Too many new connections per second for this service's limit.”
  • “This service is suspended. Contact support to resolve it.”, “This service has reached its expiry date. Renew it to continue.” and “This service has used its traffic allowance. Add traffic to continue.”
  • “Your trial has closed. Buy a paid plan to continue.”
  • “The proxy is at capacity right now. Try again in a moment.”

A targeting error is answered before any exit is chosen, so it uses no traffic. For example, country-usa is refused because country codes have two letters (country-us), and -country-us-country-gb is refused because an option appears twice. The How to connect guide lists every option each product accepts.

If a 407 carries no sentence at all, your address has most likely been locked out for about a minute after repeated failed logins. Stop retrying, fix the credentials, then try again.

Two setup details also produce 407s. A password with special characters must be percent-encoded when it is written inside a proxy URL (@ becomes %40). And a trusted IP only admits connections from the public address you added; see trusted IPs.

Why do 403 and 429 come from the website, not the proxy?

Once the tunnel is open, the status codes you see are the website's. A 403 Forbidden means the site understood the request and refused it (RFC 9110). A 429 Too Many Requests means you sent more requests than the site allows in a period, and the site may add a Retry-After header that says when to try again (RFC 6585).

A different exit address does not make a refused request permitted. Treat both codes as the site's instructions: honor Retry-After, lower concurrency, space out requests, and check the site's terms and robots.txt. Under the TrueProxies acceptable use policy, you are responsible for following the terms of every site you reach through the service.

One exception: a 403 returned as the answer to CONNECT, before any TLS, comes from the proxy. On TrueProxies that means the destination is on the network's blocked list.

What do 502, 503 and 504 mean through a proxy?

These are gateway errors: something between you and the site could not get a usable answer (RFC 9110). Where the code appears tells you which side failed.

  • Answer to CONNECT, with a reason. On TrueProxies, a 502 whose X-Proxy-Reason reads “Datacenter IPv6 proxies reach IPv6 destinations only. This destination has no IPv6 address.” means the site has no IPv6 address. Use Residential IPv4 for it, and check your other targets for IPv6.
  • Answer to CONNECT, no reason. The gateway could not open a connection to that host and port. The site may have refused or not answered, a country you targeted may have no exit free at that moment, or the port may be closed. On the free trial only ports 80 and 443 are open, and outgoing mail ports are closed on every service.
  • After the tunnel opened. The website or its CDN returned the error. The proxy did its job; retry later with backoff.

A 504 Gateway Timeout comes from a gateway that waited too long for the server behind it. After the tunnel opens, that gateway belongs to the website.

Why does a proxy connection time out?

A timeout means no answer arrived before your client gave up. Find the stage first: connecting to the proxy, the proxy opening the tunnel, the TLS handshake with the site, or waiting for the site's first byte.

  • Connecting to the proxy. Check the connection host and port on your service page, and that your network allows outgoing connections to that port.
  • Opening the tunnel. The site is slow to accept connections, or a residential exit went away during setup. Retry once. If one site times out while others work, the site is the cause.
  • TLS or first byte. The site is slow to respond. Raise your client's read timeout for slow pages instead of retrying at once.
  • DNS. With SOCKS5, let the proxy resolve hostnames (socks5h://) so a local resolver problem does not look like a proxy timeout.

The Proxy Checker separates a proxy problem from a site problem: it reports whether the proxy route works and, separately, whether a selected target answered, each within eight seconds. Its error code guide explains each stage. On your service page, Usage history lists recorded errors by type, such as Connection setup timeout, Read timeout and DNS error.

Why is my proxy slow?

A slow proxy is usually held back by one of four things: the plan speed, the website, the distance to the exit, or how your client uses connections.

  • Plan speed. Residential IPv4 Unlimited plans run from 10 Mbps to 1 Gbps, and Datacenter IPv6 plans from 25 to 400 Mbps. Plan speed is the ceiling for the service at its peak, not what each connection or each site will deliver. Residential IPv4 GB-based is charged by traffic, not by plan speed.
  • The website. A site can limit how fast it serves one client. If one site is slow and others are not, the site is the limit.
  • Distance and exit type. Setup takes longer as the distance between you, the exit and the site grows. Residential exits run on household connections, so their speed varies from exit to exit.
  • Connections. A single connection may not fill a fast plan. Opening many at once can reach the service's open-connection limit and draw a 407.

Measure before you change plans. Compare Download speed in Live traffic on your service page with your plan speed: if you are well below it, a faster plan will not help. The latency vs speed guide explains why a fast first response and a fast download are different measurements, and sizing your plan speed shows how to measure a real batch.

How do you troubleshoot a SOCKS5 proxy error?

SOCKS5 cannot tell you why it refused. Its username and password step returns one status byte, success or failure, with no text (RFC 1929), and a refused destination comes back as a short reply code such as network unreachable (RFC 1928).

To see the reason, send the same username once over HTTP. The connection host serves HTTP on port 8080 and SOCKS5 on port 1080 with the same credentials, so the HTTP answer names the problem:

Read the reason a SOCKS5 refusal cannot carrybash
# Same username and password as your SOCKS5 client, sent over HTTP
curl -v -x http://YOUR_HOST:8080 -U "YOUR_USERNAME-country-us:YOUR_PASSWORD" https://example.com/ -o /dev/null

Read the X-Proxy-Reason line, fix the username, then switch back to SOCKS5. With SOCKS5, prefer socks5h:// (or --socks5-hostname in curl) so hostnames are resolved at the proxy.

What should you send to support?

If these steps do not explain an error, contact support with:

  • The time of the error in UTC, and the product: Residential IPv4 Unlimited, Residential IPv4 GB-based or Datacenter IPv6
  • The protocol and port: HTTP 8080, HTTPS 8443 or SOCKS5 1080
  • The target hostname and the status code you saw
  • The exact X-Proxy-Reason text, if there was one
  • Your username. Never send your proxy password.

TrueProxies

Related articles

5 min readSeptember 29, 2026

How to check if a website supports IPv6

A website supports IPv6 when its hostname publishes an AAAA record and its server answers on that address. Look up the record with dig or nslookup, confirm a real connection with curl -6, then test every host the page loads, because one IPv4-only script, font or API can break the page over IPv6.

Read article
8 min readMarch 21, 2026

Rotating proxies vs sticky sessions: how to choose

A rotating proxy picks an exit IP from its pool for each new connection or request; a sticky session reuses one exit IP for every connection that carries the same session ID, while that IP stays available. Use rotation for independent requests and a sticky session when a permitted login, cart or multi-page flow needs one address.

Read article

Ready to compare current options?

Try 1 hour of Residential IPv4 Unlimited at 10 Mbps, free. No card required.