SOCKS5 Proxy Checker

Test whether a SOCKS5 proxy can connect, authenticate, reach your target, and route traffic through the expected exit IP.

Your current IPUsed only as a reference when you compare a proxy exit IP.

Test SOCKS5 Proxies

Add one SOCKS5 proxy per line. We accept host:port, SOCKS5 URLs, IPv6 addresses, and optional username/password authentication.

Credentials are masked and never saved in your session history.

Check Settings

Leave blank to use the Rola IP HTTPS probe.

This version verifies TCP proxy connectivity only. UDP ASSOCIATE is not tested.

SOCKS5 Check Results

Your SOCKS5 check results will appear here.

Recent Checks

Up to 5 recent checks are kept for 30 minutes in this browser session.

No session history saved yet.

Need More Reliable Proxies?

Residential Proxies

Use IPs from real home networks for workflows that need broader geographic coverage and natural network characteristics.

View Residential Proxies

ISP Proxies

Choose stable static proxy infrastructure for repeated tasks that need a fixed identity and reliable response.

View ISP Proxies

Datacenter Proxies

Use fast dedicated proxy capacity for predictable high-concurrency technical tasks.

View Datacenter Proxies

How the SOCKS5 Proxy Checker Works

TL;DR: This tool checks whether a SOCKS5 proxy can establish a TCP connection, complete protocol negotiation, authenticate when required, reach an allowed target, and return an exit IP. This version does not test UDP ASSOCIATE.

What a SOCKS5 proxy check tests

A working SOCKS5 proxy must accept a TCP connection, choose an authentication method, handle a CONNECT request, and establish routing to the target. Any stage can fail.

How to read SOCKS5 CONNECT reply codes

After authentication, the proxy responds to a CONNECT request with a one-byte reply code. 0x00 means success; 0x01 through 0x08 help you locate where routing failed.

  • 0x00 — Succeeded — The proxy accepted the CONNECT request and established routing to the target.
  • 0x01 — General SOCKS failure — The proxy rejected the request for an unspecified server-side reason. Retry with another target or proxy.
  • 0x02 — Connection not allowed — The proxy ruleset blocked this destination or connection type. Try another allowed public target.
  • 0x03 — Network unreachable — The proxy could not reach the target network. This often points to routing or upstream network issues.
  • 0x04 — Host unreachable — The target host could not be reached through the proxy path. Confirm the hostname or IP is correct and public.
  • 0x05 — Connection refused — The target host rejected the TCP connection. The proxy path may be fine, but the destination port is closed or filtered.
  • 0x06 — TTL expired — The connection timed out before completion. Increase the timeout or retry when the network is less congested.
  • 0x07 — Command not supported — The proxy does not support the requested SOCKS command. This checker uses CONNECT for TCP routing.
  • 0x08 — Address type not supported — The proxy does not support the requested address format, such as a hostname or IPv6 form it cannot handle.

SOCKS5 authentication methods

Some SOCKS5 proxies require no authentication while others require a username and password. Authentication failures are usually related to credentials, method mismatch, or IP allowlists.

Web URL vs TCP host:port tests

Web mode checks access to a public HTTP(S) page. TCP host:port mode is for mail, FTP, games, and custom application endpoints. TCP tests verify routing only, not application login.

Proxy DNS resolution and SOCKS5H

With proxy DNS, target hostnames are resolved through the SOCKS5 connection. Local resolution may expose the domain you want to reach to your DNS provider.

Why this version tests TCP only

SOCKS5 can support UDP ASSOCIATE, but this checker currently verifies TCP connectivity only. Applications that depend on UDP need separate testing.

What IP Type means in the results

IP Type describes the network category of the exit IP, such as Residential, ISP, Datacenter, or Hosting/CDN. It is a point-in-time intelligence signal, not a guarantee that a site will accept or reject the IP.

SOCKS5 Proxy Checker FAQ

What is a SOCKS5 proxy checker?

A SOCKS5 proxy checker verifies whether a proxy can complete a SOCKS5 TCP connection, negotiate an authentication method, open a route to a permitted target, and return an exit IP. It helps separate address, authentication, routing, and target-access failures.

Can I test SOCKS5 proxies with a username and password?

Yes. Enter a SOCKS5 URL with credentials or a supported host, port, username, and password format. Credentials are masked in results and are not included in session history or file exports.

Why did my SOCKS5 proxy fail authentication?

Authentication can fail when the username or password is incorrect, the provider requires a different authentication method, your account has expired, or the provider only allows connections from approved source IP addresses.

Can I test a TCP port through a SOCKS5 proxy?

Yes. Choose TCP host:port and enter one public destination, such as a mail or application endpoint. The test verifies TCP route creation through the proxy. It does not perform a service-specific login or protocol exchange.

Does this checker test UDP or UDP ASSOCIATE?

No. This version verifies TCP proxy connectivity only. A SOCKS5 proxy may support TCP CONNECT while its UDP forwarding behavior is unavailable or configured differently.

What is the difference between proxy DNS and local DNS resolution?

With proxy DNS, the SOCKS5 proxy resolves the destination hostname. With local DNS, your own resolver looks up the name before the proxy connection begins. Local resolution can expose the domain to your DNS resolver.

Why is a proxy Live but the target is blocked?

Live means the SOCKS5 connection and route were established. A target can still return an error because of its own access controls, rate limits, location rules, or application requirements. Test another permitted target before discarding the proxy.

What does IP Type mean in the results?

IP Type is a detected category for the proxy exit IP, including Residential, ISP, Datacenter, or Hosting/CDN. It can help explain network characteristics, but it does not guarantee how a specific target will treat the proxy.

Are my proxy credentials saved or exported?

Credentials are used only for the active check and are not saved in session history. TXT and CSV exports never contain credentials. You can choose to copy credentials only in the current browser session after confirming the risk.

How accurate are SOCKS5 proxy check results?

Results describe the connection path observed at the time of the test. Proxy availability, routing, target policies, and network conditions can change, so a later request may produce a different outcome.

Start routing through stable ROLA IP proxies today

Try for Free