Geonode logo
Developer, scraping & anti-detect tools

ProxyChains Proxy List Free ProxyChains and Paid Setup

ProxyChains works on

  • Linux
  • macOS
  • BSD

Key facts

  • Free ProxyChains list

    ProxyChains comes with no proxies. You add each as a line under [ProxyList] in proxychains.conf, and the Free proxy list tab converts the Geonode free proxy list into those lines with one command.

  • When the chain fails

    The program gets 'connection refused' and never falls back to a direct connection.

  • [ProxyList] comes last, 512 entries max

    Every line after [ProxyList] is read as a proxy, so an option placed below it stops proxychains, usually with 'invalid item in proxylist section'. Entries past the 512th are ignored.

Proxy types you can list in proxychains.conf

Each line starts with socks5, socks4, http or raw (plain forwarding, no handshake). There is no https keyword.

NameWorks InAuthBlocking ResistanceBest ForWhere To Get
socks5Any hop, IPv4 or IPv6 targetsUSER and PASS fields, or noneDecided by the exit IPPaid proxies with a login, free SOCKS5 entriesGeonode residential and datacenter SOCKS5 ports, Geonode free list
socks4Any hop, IPv4 targets only. With proxy_dns, hostnames go as SOCKS4aNone. USER goes out as the user ID, PASS is ignoredSame as socks5Free SOCKS4 entries and TorGeonode free list, or a local tor service
httpAny hop, via CONNECT host:port, which the proxy must allowBasic, from USER and PASS, or noneSame as socks5HTTPS free entries, paid HTTP portsGeonode residential and datacenter HTTP ports, Geonode free list

Which proxy type to use with ProxyChains

Sites only see the last proxy in the chain. Its IP type decides whether requests get through.

One assigned source IP

ISP proxies

from $1.25/IP

Use it when a server accepts SSH or API sessions only from an allowlisted address.

Your own servers, bulk jobs

Datacenter proxies

from $0.14/GB

Billed per GB. Suits hosts you control and targets that don't filter datacenter ranges.

Testing the config

Free public proxies

Free

No uptime guarantee, and the operator can read anything you send unencrypted.

How to set up a proxy in ProxyChains

Each proxy is one [ProxyList] line: type, IP, port and, for paid proxies, username and password.

  1. Install it with sudo apt install proxychains4.

  2. Copy the sample config to your home folder: mkdir -p ~/.proxychains, then cp /etc/proxychains4.conf ~/.proxychains/proxychains.conf. proxychains4 reads this copy before /etc, and you can edit it without sudo.

  3. Pick a chain mode: strict_chain, the sample default, uses every proxy in order and fails if one is down; dynamic_chain skips dead ones.

  4. round_robin_chain and random_chain use chain_len proxies per connection, in turn or at random.

  5. Leave exactly one mode uncommented. If two are active, the one lower in the file wins, and strict_chain sits below dynamic_chain.

  6. Keep the proxy_dns line uncommented.

  7. Under [ProxyList], replace the stock Tor entry socks4 127.0.0.1 9050 with one proxy per line: socks5 203.0.113.10 1080 or http 203.0.113.20 8080 USER PASS. socks5://USER:PASS@203.0.113.10:1080 also works.

  8. Prefix the command: proxychains4 wget https://example.com/file.tar.gz. -q hides the status lines.

Check detailed instructions on our blog:

Read the blog post

How to check that ProxyChains uses the proxy

  1. Run curl ifconfig.me, then proxychains4 curl ifconfig.me; the second should print the proxy's IP. On a Mac, brew install curl and run the second with $(brew --prefix)/opt/curl/bin/curl.

  2. Check the status lines: config file found names the file in use, and a DLL init: proxychains-ng line means the hook loaded.

  3. Look for one line per connection, like [proxychains] Strict chain ... 203.0.113.10:1080 ... ifconfig.me:80 ... OK.

How to stop proxying a program

  1. Run the command without the proxychains4 prefix. Nothing outside that program is affected.

  2. To keep local services direct, uncomment localnet 127.0.0.0/255.0.0.0 and leave remote_dns_subnet at 224, never 127. With proxy_dns on, localnet matches only IP addresses and /etc/hosts names.

  3. Switch configs per command with -f, or per shell session with PROXYCHAINS_CONF_FILE.

Common ProxyChains errors and fixes

  • Free entries end in timeout or need more proxies

    Cause
    A bare timeout means the entry never accepted the connection. <--socket error or timeout! means it answered but the handshake or the hop to the target failed. !!!need more proxies!!! means too few live entries remain for chain_len.
    Fix
    Load a fresh list filtered by Last Checked and rerun. Test entries in the Geonode proxy checker first.
  • The chain line ends in <--denied

    Cause
    A SOCKS5 server rejected the login or wanted one, or an HTTP proxy replied with something other than 200, such as 407.
    Fix
    Add the username and password after the port. With IP whitelisting, drop both and whitelist the machine's public IP in the dashboard.
  • A program ignores proxychains and shows your IP

    Cause
    The hook never loaded or never sees the connection. Go programs call the kernel through their own wrappers instead of libc, even when dynamically linked. For setuid programs started without root, the loader ignores the preload path.
    Fix
    Use the program's own proxy setting. Many Go tools read HTTPS_PROXY. Run setuid tools as root.
  • Edits to proxychains.conf change nothing

    Cause
    Another file wins. A leftover /etc/proxychains.conf from 3.1 outranks /etc/proxychains4.conf, and ./proxychains.conf outranks both. A mistyped -f path is skipped silently.
    Fix
    Edit the file named in the config file found line, or pass a full -f path and check that line.

More for ProxyChains users

ProxyChains proxy FAQ

The Geonode free proxy list has HTTP, HTTPS, SOCKS4 and SOCKS5 entries. Filter it to one protocol, copy its API URL and convert each ip and port with jq into a line like socks5 IP PORT.

Not natively. The project supports Linux, BSD, macOS and Haiku. Under WSL it wraps Linux programs only, so Windows apps need a client such as Proxifier.

proxychains4 takes the first file it finds: the -f path or PROXYCHAINS_CONF_FILE, ./proxychains.conf, ~/.proxychains/proxychains.conf, then $(brew --prefix)/etc/proxychains.conf on a Mac or /etc/proxychains.conf. Debian-based distros ship /etc/proxychains4.conf, checked last.

No. proxychains handles TCP connections only; UDP, ping's ICMP packets and nmap's SYN scan never enter the chain. With nmap, use -sT -Pn.

Run the tor service and keep the stock entry socks4 127.0.0.1 9050. Tor Browser uses port 9150 instead. Leave proxy_dns on so .onion addresses resolve inside Tor.

proxychains4 is the proxychains-ng command, the maintained 4.x line. Plain proxychains was the unmaintained 3.1, and current Debian, Ubuntu and Kali point it at proxychains4.

The program gets placeholder addresses from 224.x.x.x, and the last proxy resolves the real hostname. This covers only lookups through libc; Chromium and curl built with c-ares can resolve names themselves and bypass it. Without proxy_dns, names resolve locally.