Geonode logo
Browsers & operating systems

Safari Proxy Setup on Mac, iPhone and iPad

Safari works on

  • macOS
  • iOS
  • iPadOS
  • visionOS

Key facts

  • The proxy covers the whole device

    Safari has no proxy of its own. On a Mac, Safari > Settings > Advanced > Proxies > Change Settings opens the macOS network settings; on iPhone it's Settings > Wi-Fi > (i) > Configure Proxy. The proxy also carries Mail, the App Store and any other app that follows the system settings, and you can't limit it to Safari.

  • No proxy extensions

    Safari's extension API has no proxy feature. FoxyProxy and the Chrome proxy switchers have no Safari version that changes your IP.

  • iCloud Private Relay is not a proxy you control

    Private Relay (iCloud+) hides your IP in Safari, but the IP it gives you stays near your real region. You can't pick a country or a fixed address.

Proxy options Safari can use

The macOS Proxies screen also has Auto proxy discovery; the four below are the ones you fill in by hand. iPhone and iPad offer only the HTTP proxy and a PAC file, and only on Wi-Fi.

NameWorks InAuthBlocking ResistanceBest ForWhere To Get
Web proxy (HTTP)Safari on macOS for http:// pages; on iPhone and iPad the Wi-Fi HTTP proxy carries all Safari trafficUsername and password (Proxy server requires password on Mac, Authentication on iPhone)Set by the IP type behind itEveryday browsing through a paid proxyGeonode residential, ISP or datacenter proxies; Geonode free list
Secure web proxy (HTTPS)Safari on macOS for https:// pages, which is almost every siteUsername and passwordSet by the IP type behind itPairing with the web proxy so both kinds of pages use the same IPThe same host and port as the HTTP proxy
SOCKS proxymacOS only; not offered on iPhone or iPadUnreliable with a login on macOS, see the fixes belowSet by the IP type behind itSOCKS proxies that need no loginGeonode free list (SOCKS4 and SOCKS5 entries)
Automatic proxy configuration (PAC file)macOS, and iPhone and iPad under Configure Proxy > AutomaticSet by the proxies the file points toSet by the proxies the file points toSending only some sites through a proxy, or company networksYour network administrator, or a PAC file you host yourself

Which proxy type to use with Safari

Safari accepts all four. Which one gets through depends on the sites you open.

Best for Safari

Residential proxies

from $0.27/GB

Sites see a home connection in the country you choose. A sticky session holds one IP for up to 24 hours, long enough to stay signed in.

Best for accounts

ISP proxies

from $1.25/IP

The IP never changes, and a bank, shop or social site sees the same address at every sign-in.

Public pages only

Datacenter proxies

from $0.14/GB

Google in Safari shows CAPTCHAs to datacenter IPs more often than to home IPs, and every app on the Mac shares that one IP.

Testing only

Free public proxies

Free

The whole Mac goes through it, including iCloud and Mail sign-ins, and whoever runs a free proxy can see which sites you open. Don't sign in to any account through one.

How to set up a proxy for Safari

Copy the proxy host, port, username and password from your provider's dashboard before you start.

  1. In Safari, choose Safari > Settings, then click Advanced.

  2. Next to Proxies, click Change Settings. In Network, select your service (Wi-Fi or Ethernet), click Details, then Proxies.

  3. Turn on Web proxy (HTTP) and enter the host in Server and the port in Port.

  4. Turn on Proxy server requires password and enter the proxy username and password.

  5. Turn on Secure web proxy (HTTPS) and enter the same host, port, username and password.

  6. Optionally add sites that should skip the proxy under Bypass proxy settings for these hosts & domains, separated by commas.

  7. Click OK. Enter your Mac user password if macOS asks for it.

  8. Reload the page in Safari. If a sign-in prompt for the proxy appears, enter the proxy username and password.

Check detailed instructions on our blog:

Read the blog post

How to check that Safari uses the proxy

  1. Open geonode.com/what-is-my-ip in Safari. It should show the proxy's IP and country, not yours.

  2. If the IP is neither yours nor the proxy's, iCloud Private Relay may be on. Turn it off in System Settings > [your name] > iCloud > Private Relay and reload.

  3. On a Mac, run scutil --proxy in Terminal. HTTPEnable and HTTPSEnable set to 1 mean macOS applies the web proxies, and the host and port are listed next to them.

How to turn the proxy off in Safari

  1. Mac: open Safari > Settings > Advanced, click Change Settings next to Proxies, select your service, click Details > Proxies, turn off each proxy you turned on and click OK.

  2. iPhone and iPad: go to Settings > Wi-Fi, tap (i) next to the network, tap Configure Proxy, select Off and tap Save.

Common Safari proxy problems and fixes

  • A SOCKS proxy with a username and password does not connect

    Cause
    The fields for a SOCKS login exist, but on macOS Sonoma 14.3 and 14.4 users report the system SOCKS proxy never sends them and offers the server only 'no authentication'. We haven't retested this on newer macOS.
    Fix
    Test on your macOS version. If it fails, use the HTTP endpoint of the same proxy plan in Web proxy (HTTP) and Secure web proxy (HTTPS), and keep SOCKS for proxies without a login.
  • "Safari can't connect to the server" after you set the proxy

    Cause
    Wrong host or port, the proxy is offline, or your IP isn't whitelisted on the proxy
    Fix
    Check the host and port against the dashboard, test the proxy with the proxy checker, then turn the proxy off to confirm Safari loads pages without it.
  • Some sites show the proxy IP and others show your real IP

    Cause
    Only one of Web proxy (HTTP) and Secure web proxy (HTTPS) is turned on
    Fix
    Turn on both and enter the same host and port in each. Also clear the bypass list if a site you want to proxy is in it.
  • Safari keeps asking for a password, or pages show error 407

    Cause
    Wrong proxy username or password, or your account login typed in place of the proxy credentials
    Fix
    Copy the proxy username and password from the proxy dashboard and enter them again. Your Geonode account email and password won't work here.
  • The proxy stopped working after you changed networks

    Cause
    The proxy is saved per network service on a Mac and per Wi-Fi network on iPhone; cellular data never uses the Wi-Fi proxy
    Fix
    Set the proxy again on the Ethernet service or new Wi-Fi network. For Safari on cellular, use a proxy app such as Shadowrocket.
  • The Proxies fields are greyed out

    Cause
    A configuration profile or your company's device management controls them
    Fix
    Check System Settings > General > Device Management. If a profile sets the proxy, ask whoever manages the Mac to change it.

More for Safari users

Safari proxy FAQ

No. On a Mac, Safari > Settings > Advanced > Change Settings opens the macOS Proxies screen, and on iPhone the proxy is set per Wi-Fi network in Settings. Every app that follows the system proxy uses the same one.

On a Mac, yes, through SOCKS proxy in the macOS Proxies screen. SOCKS proxies without a login work; with a username and password, users on macOS Sonoma 14.3 and 14.4 report failures, so test on your version or use the HTTP endpoint. iPhone and iPad have no SOCKS option in Wi-Fi settings.

Go to Settings > Wi-Fi, tap (i) next to your network, tap Configure Proxy, choose Manual and enter Server and Port. Turn on Authentication if the proxy needs a login, then tap Save.

No. Safari always uses the macOS or iOS system proxy, and other apps on the device go through it as well. For a proxy in one browser only, use Firefox, which has its own Network Settings, or on a Mac a per-app proxy tool such as Proxifier.

Not one that changes your IP. Apple gives Safari extensions no way to set a proxy, so switchers like FoxyProxy exist for Chrome, Edge and Firefox but not for Safari.

It works like one. Safari traffic passes through two relays, one run by Apple and one by a partner company, and sites never see your IP. You can't pick a country, though, and the IP stays near your region, which makes it useless for geo-checks.