Tutorial29 September 20268 min read

ERR_PROXY_CONNECTION_FAILED and other Chrome proxy errors

ERR_PROXY_CONNECTION_FAILED: Chrome cannot reach the proxy. ERR_TUNNEL_CONNECTION_FAILED: the proxy will not open a tunnel. Causes we reproduced, and fixes.

ERR_PROXY_CONNECTION_FAILED means Chrome could not reach the proxy at all: the host or port is wrong, nothing is listening there, or a proxy is switched on in your system or an extension that you forgot about. ERR_TUNNEL_CONNECTION_FAILED means Chrome reached the proxy, but the proxy refused to open a tunnel to the site, usually over a login, a block or an unreachable site.

The two codes point at different halves of the trip, so telling them apart saves most of the guesswork. Below is what each Chrome proxy error means, the causes we reproduced, where Chrome hides the setting that is causing it, and how to tell a proxy problem from a website problem.

How we tested

Every cause on this page comes from a test we ran. We launched headless Chrome for Testing 153 (the build Playwright downloads) with --proxy-server pointed at small local proxies built to misbehave in one way each: a closed port, a proxy that answers CONNECT with 403, 429, 502 or 503, one that wants a login, one that closes the connection, and so on. Then we recorded the net::ERR_ code Chrome reported. Where we could not reproduce something, we say so.

What we set up What Chrome reported
Nothing listening at the proxy port ERR_PROXY_CONNECTION_FAILED
Proxy hostname that does not resolve ERR_PROXY_CONNECTION_FAILED
https:// proxy scheme pointed at a plain HTTP proxy ERR_PROXY_CONNECTION_FAILED
Proxy answers CONNECT with 403, 429, 502 or 503 ERR_TUNNEL_CONNECTION_FAILED
Proxy answers CONNECT with something that is not HTTP ERR_TUNNEL_CONNECTION_FAILED
Proxy login cancelled, or a wrong password and then cancelled ERR_TUNNEL_CONNECTION_FAILED
Site name that does not exist, through a working proxy ERR_TUNNEL_CONNECTION_FAILED
Username and password inside --proxy-server ERR_NO_SUPPORTED_PROXIES
A scheme Chrome does not know, such as ftp:// ERR_NO_SUPPORTED_PROXIES
Proxy sends 407 with no login method Chrome supports ERR_PROXY_AUTH_UNSUPPORTED
socks5:// pointed at an HTTP proxy ERR_SOCKS_CONNECTION_FAILED
Proxy closes the connection without answering ERR_EMPTY_RESPONSE
Proxy resets the connection ERR_CONNECTION_RESET
Proxy accepts the connection and never answers ERR_TIMED_OUT

What does ERR_PROXY_CONNECTION_FAILED mean?

Chrome tried to open a connection to the proxy's host and port and got nowhere. Nothing reached a website, so the website is not the problem. In our tests three things caused it:

  1. Wrong host or port. Nothing answered at the address Chrome was given. Compare both with the values on your service page, character by character.
  2. A proxy hostname that does not resolve. A typo in the host, or a DNS problem on your own network.
  3. The wrong scheme. A proxy entry written as https://HOST:PORT asks for an encrypted connection to the proxy itself. Your service is a plain HTTP proxy that still carries https sites through a CONNECT tunnel, so use http://.

One more cause we could not test from a lab, but that you should rule out early: a service that has lapsed or run out of balance. Check that the service still shows as active in the dashboard.

The proxy you forgot you switched on

One easy way to meet ERR_PROXY_CONNECTION_FAILED is a proxy nobody meant to be using. Chrome and Edge have no proxy form of their own. The proxy entry in Chrome's settings is a link labelled "Open your computer's proxy settings", and it leads to the operating system's panel, which every browser on the machine reads.

So a proxy you set up last month for one test, on a service you have since stopped using, can break every page in Chrome today. Look here:

  • Windows 11: Settings, then Network & internet, then Proxy. Check "Use a proxy server" under Manual proxy setup, and switch it off if you did not mean it.
  • macOS: System Settings, then Network, then your connection (Wi-Fi or Ethernet), then Details, then Proxies. Check Web proxy (HTTP) and Secure web proxy (HTTPS).

The Windows and macOS guide walks through both panels field by field.

An extension is controlling the proxy

Proxy extensions such as FoxyProxy override the system setting for one browser. When one is in charge, Chrome says so on the settings page. We loaded a small test extension that set a proxy, then opened chrome://settings/system. The proxy row read "Chrome for Testing is using proxy settings from an extension" (in ordinary Chrome the product name differs), with "Test Proxy Switcher is controlling this setting" beneath it and a Disable button.

If you see that line and the extension points at an old proxy, switch the extension to its direct or disabled mode, or disable it from that button. The browser guide shows how FoxyProxy switches between a proxy and going direct.

What does ERR_TUNNEL_CONNECTION_FAILED mean?

Chrome reached the proxy and asked it to open a tunnel to the site with CONNECT. The proxy answered with anything other than success. Every rejection we tried produced the same code: 403, 429, 502, 503 and a reply that was not HTTP at all. That is the frustrating part: Chrome hides the status code the proxy sent.

The causes we reproduced:

  • The login was refused. When the proxy asks for a username and password, Chrome shows a sign-in box. Cancel it, or type a wrong password and then cancel the box when it comes back, and the page fails with ERR_TUNNEL_CONNECTION_FAILED. Fixing a 407 covers why a correct-looking password gets refused.
  • The proxy could not reach the site. A mistyped site address through a working proxy gave ERR_TUNNEL_CONNECTION_FAILED, not a DNS error, because the proxy does the lookup and reports failure with a 502. A site that refused the connection behaved the same way.
  • The proxy refused the request. A 403 or 429 in answer to CONNECT means the proxy side said no: a limit, a blocked destination, or an account problem.

To see the status code Chrome hides, send the same request with curl. It prints the proxy's answer to CONNECT and the site's answer separately:

curl -s -o /dev/null -x "http://USERNAME:PASSWORD@HOST:PORT" \
  -w 'proxy said %{http_connect}, site said %{http_code}\n' \
  https://api.ipify.org

On our test proxies, a proxy refusing the tunnel printed proxy said 429, site said 000 alongside curl: (56) CONNECT tunnel failed, response 429. A site rate limiting through a healthy tunnel printed proxy said 200, site said 429. The first is a proxy question; the second is the site, and fixing 429 errors is the page for that. Proxy error codes lists what each proxy status usually means.

ERR_NO_SUPPORTED_PROXIES: a login in --proxy-server

This one mostly hits people automating Chrome. Chrome's --proxy-server flag takes a scheme, host and port, and nothing else. Putting USERNAME:PASSWORD@ in it made Chrome reject the whole proxy list with ERR_NO_SUPPORTED_PROXIES in our test, and so did a scheme it does not know.

Supply the login another way. Playwright's proxy option has username and password fields, and with them our test page loaded normally. The Playwright and Selenium guides show both tools. Or add your machine's public IP to the service's IP allowlist in the dashboard, after which --proxy-server=http://HOST:PORT needs no login at all.

A related trap: with a proxy that wants a login and no credentials supplied, headless Chrome did not fail. The page hung until our timeout, waiting at a sign-in box nobody could see.

ERR_PROXY_AUTH_UNSUPPORTED

We produced this only with a proxy that answered 407 while naming a login method Chrome does not support, or naming none. Your service asks for a plain username and password, which Chrome handles. If you see this code, suspect a different proxy in the path, such as an office or school network proxy, and check the system settings above.

Other codes you may meet

  • ERR_SOCKS_CONNECTION_FAILED: the proxy entry says socks5:// but the proxy speaks HTTP, or it wants a SOCKS5 login, which Chrome cannot send. Use http://, or allowlist your IP.
  • ERR_EMPTY_RESPONSE and ERR_CONNECTION_RESET: the proxy dropped the connection before answering. Try again, then try from a different network to rule out a firewall on yours.
  • ERR_TIMED_OUT: the proxy accepted the connection and said nothing. Proxy timeout errors splits that time up with curl.

chrome://net-internals: clearing Chrome's memory of a proxy

Chrome keeps state between attempts: open connections to the proxy, and a list of proxies that recently failed. After you fix a setting, clear both before you judge the fix.

  • chrome://net-internals/#proxy has two buttons: Re-apply settings and Clear bad proxies. In the version we tested, that is all the page offered. It does not list the settings in force, so check those on the settings page.
  • chrome://net-internals/#sockets has Close idle sockets and Flush socket pools. Flushing makes Chrome open fresh connections, and with them fresh tunnels. That also matters on residential Randomize IP, where a kept-alive tunnel keeps the same exit address.

When it is the site, not the proxy

Some failures look like proxy errors and are not:

  • A normal page with a 403 or a captcha. Chrome loaded something, so the tunnel worked. The site is refusing the exit IP or your behaviour. Why your scraper started getting blocked goes through the causes in order.
  • A plain http:// page showing an error from the proxy. For unencrypted pages Chrome displays whatever the proxy sent, so a 502 appears as a page instead of a net::ERR_ code.
  • ERR_TUNNEL_CONNECTION_FAILED on one site only. Open https://api.ipify.org through the same proxy. If it loads and shows an address that is not yours, the proxy works and the problem sits between the exit and that one site.

Quick answers

How do I fix ERR_PROXY_CONNECTION_FAILED? Check which proxy Chrome is using (system settings or an extension), compare the host and port with your service page, and confirm the service is active. If you did not mean to use a proxy, switch it off.

Is ERR_TUNNEL_CONNECTION_FAILED my fault or the site's? Either. Run the curl command above: a non-200 "proxy said" is the proxy side, a 200 followed by an error from the site is the site.

Why does Chrome not ask for my proxy password? It asks only when the proxy requests a login, and headless Chrome cannot show the box. Supply the credentials through your automation tool or use the IP allowlist.

Can I put user:pass in Chrome's proxy settings? No. Enter the host and port, and type the login in the sign-in box, or use an extension with login fields.

Next step

Open https://api.ipify.org in the proxied browser. If it loads and shows an address that is not yours, the proxy is working and anything still failing is between the exit and your target. If you are stuck, post the error code in Discord along with the curl output above, with your password removed.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord