Windows Proxy Clients 2026: System Settings, Proxifier and TUN
Windows has several proxy settings because applications use different network stacks. Choose the setting your app reads before installing another client.
Before you configure anything
- Windows proxy settings cover applications that use those settings; they do not force every connection through a proxy.
- Use a per-app client when a desktop application has no suitable proxy option. Start with one executable.
- Check WSL, containers and browser automation separately from the Windows browser.
Choose the smallest routing scope
| Layer | Start here when | Separate check |
|---|---|---|
| Windows proxy settings | The browser or app honors system configuration | Extensions and managed policy can override settings |
| Application setting | The app supports your endpoint directly | Protocol and credentials must match |
| Per-app routing client | The app has no suitable proxy option | Executable rules, helpers and DNS |
| TUN client | You need broader capture and routing rules | Local access, IPv6 and failure behavior |
For Chrome or Edge browsing, start with a supported HTTP endpoint in Windows settings. If you need to switch proxy profiles or select domains, a browser extension can manage that scope. If a desktop app has no proxy setting, a routing client such as Proxifier or ProxiFyre may be appropriate.
Whole-device TUN mode creates a virtual network interface. It is useful when several applications need coordinated routing, but it also introduces route priorities, DNS handling and local-network exclusions. Turning it on before verifying the endpoint makes troubleshooting harder.
Record the current proxy settings before changing them. A corporate setup script or managed setting may serve an existing purpose. Test on a separate browser profile where practical, then check the application you intend to route. The SOCKS5 guide explains why an HTTP endpoint and a SOCKS5 endpoint from the same provider can behave differently.
Set an HTTP proxy in Windows 11
Microsoft's current instructions place manual setup under Settings, Network & internet, Proxy. Windows also supports automatic discovery and setup scripts. Use the method supplied by your organization or proxy provider.
- Open Settings โ Network & internet โ Proxy.
- Under Manual proxy setup, open Set up beside Use a proxy server.
- Enable the setting and enter the host and port in their separate fields. Do not paste the entire credential string into the address box.
- Review the exception list. An excluded destination connects directly. Save, then reopen the target browser.
- If the proxy requires HTTP authentication, complete the application's authentication prompt. Confirm the exit address at what is my IP.
The manual dialog is not a complete SOCKS5 client with credential management. If your order only supplies authenticated SOCKS5, use an application that supports it or a routing client. For browser-specific differences, continue with Chrome, Edge and Firefox setup.
To undo this change, return to the same dialog and disable the manually added proxy. Restore a previous setup-script setting only if you changed it during the test.
Route one application with Proxifier
Proxifier documents TCP routing, application rules and proxy-side DNS. It is a paid client for forwarding connections; buy or supply the proxy endpoint separately. Check the vendor's current edition and operating-system requirements before installing.
Add the server under the proxy-server configuration and select its real protocol. For SOCKS5, enable the username/password fields if required. Run the client's proxy check before creating broad rules. Its server configuration documentation distinguishes ordinary HTTP proxying from its HTTPS/CONNECT mode, so use the documented meaning rather than guessing from a protocol label.
Create a rule for a single application executable and keep the default route direct during the first test. Open the app, make one request and inspect the connection log. If the app starts helper processes, the process making the network connection may differ from the launcher you selected.
Avoid routing the same request twice. If you configure the app to use the upstream proxy itself, then also force the app's connection to that server through a second proxy rule, you can create an unintended chain. Choose either the app's own configuration or the routing client's rule for the first test.
For DNS, inspect the client's name-resolution settings and test the actual workflow. Do not assume automatic detection means every hostname is resolved remotely. Keep local hostnames and local services reachable if the application needs them.
When another Windows client fits better
ProxiFyre
The current ProxiFyre project documents a Windows GUI, service operation and per-application SOCKS5 routing for TCP and UDP. Older descriptions that present it only as a JSON file miss its current interface. It installs networking components, so follow the maintainer's package and prerequisite instructions. Server-side UDP support is still required.
Clash Verge Rev and v2rayN
Clash Verge Rev exposes system-proxy and TUN modes around the Mihomo core. v2rayN supports several cores and desktop platforms. These clients suit users who need rule-based routing or manage several upstreams. They require more configuration knowledge than a single browser proxy setting.
A subscription URL is a configuration source. It is not the same thing as the host and port of one proxy. For a plain SOCKS5 endpoint, create an outbound entry using the format the selected core expects. Mihomo's SOCKS documentation lists server, port and optional credential fields.
NetDetour
NetDetour documents application routing, DNS handling, SSH tunneling and proxy testing. Compare its current Windows offering when you need those features. We do not rank clients by unmeasured speed or assume that their operating-system support is identical. The alternatives guide compares the routing approaches.
PowerShell, WSL and AI tools need their own check
Windows includes several command environments. Use curl.exe when you mean the curl binary; in some PowerShell environments, curl resolves to an alias instead. Check the installed command before copying options.
curl.exe --fail --show-error --connect-timeout 10 --max-time 30 --proxy socks5h://192.0.2.10:1080 --proxy-user proxy-user https://api.ipify.org
Replace the sample endpoint. With no password after the username, curl requests the password interactively. Run the same request without proxy options to establish the direct baseline if you are not already using a broader routing client.
WSL is another environment. The Linux process may use a different route or proxy configuration from a Windows browser. Containers add another boundary. Verify from inside the process environment that performs the network request; our Linux guide covers those layers.
For local browser automation, configure the browser launch or context explicitly. Playwright's proxy API documents HTTP credentials separately from the server address. An AI agent that launches a browser does not necessarily reuse the proxy setting used by its model API client.
If your workflow uses a remote browser, set its proxy where the remote session is created. A Windows routing client can route your connection to the remote service, but it cannot choose the remote browser's website-facing IP. See Browserbase setup and Browser Use setup for that distinction.
Diagnose the symptom before replacing the client
The browser still shows the original IP
Check that the proxy is enabled and that the test destination is not in an exception list. A proxy extension may override system settings. A per-app rule may target the wrong executable. Use the client's log to identify which route handled the test.
Credentials work in one app but fail in another
Compare protocol support, not only the copied password. Authenticated SOCKS5 is a common browser compatibility problem. Try the provider's supported HTTP endpoint or an upstream-authenticating local client. Do not disable authentication on a remotely reachable listener to make a client connect.
Browsing works but another app fails
The app may ignore Windows settings, need UDP, use a helper process or run inside another environment. Test the app's actual connection. An IP checker tab in Edge does not establish that a game, a command-line tool or a container follows the same route.
Internet access stops after quitting the client
A system-proxy entry can still point to a local listener that has stopped. Inspect the Windows proxy dialog and the client's system-proxy setting. Remove only the setting you added, then test direct access. If TUN mode changed routes, use the client's own disable/disconnect action and check recovery before uninstalling.
A short acceptance test for a working configuration
Keep a small record with the client version, endpoint protocol, intended app and date. Verify the exit IP in that app, inspect DNS behavior and check access to any necessary local service. Disconnect the proxy and observe whether the app fails, falls back to direct access or reconnects through another rule.
The failure test shows whether an outage could send the application onto a different network. A setup that looks correct only while the proxy is healthy can behave differently during rotation or a brief outage. Repeat the test after reconnecting Wi-Fi or restarting Windows if the workflow is expected to survive those events.
For quality-assurance work, compare the same request and session conditions across runs. For dedicated mobile proxies, agree on rotation behavior before long-running jobs. Keep the endpoint stable while a logged-in task is in progress unless the application explicitly handles reconnection.
Sources and review scope
This guide was checked against the documentation below on October 11, 2026. Software behavior depends on the installed version, operating system and proxy service. Configuration examples are illustrative; this is a documentation review, not a benchmark of every client.
Frequently asked questions
Continue with your device
Protocol basics, operating-system setup and client choices in one series.
Related workflows
Compare native settings, per-app clients and virtual interfaces.
Check shell, package manager and container traffic separately.
Route the browser controlled by an AI agent.
Keep location and session conditions reproducible.