Tutorial8 October 20266 min read

Deluge proxy settings: SOCKS5 with a login, set once on the daemon

Deluge proxy settings: choose Socks5 Auth in Edit > Preferences > Proxy. What each checkbox does, what still goes direct, and what a daemon setup changes.

Deluge proxy settings are under Edit > Preferences > Proxy. Choose "Socks5 Auth", enter the host, port, username and password, and apply. Unlike some clients, Deluge proxies peers, trackers and hostname lookups as soon as you pick a type: those three boxes are ticked by default in its source. What it cannot send through our proxy is anything that travels over UDP.

Below: what each of Deluge's options does, the limits that apply whatever you tick, and what changes when Deluge runs as a daemon on another machine.

Before you set it up

Most people who run Deluge are seeding or fetching things that are fine to share: distribution images, open-source releases, research datasets, Internet Archive and Creative Commons items. Those need no proxy. When the project also offers a plain HTTP mirror, that is the cheaper way to get one file, since nothing touches a metered proxy.

A proxy makes sense when you want Deluge's traffic, and only Deluge's, to leave from a separate address, for example a home server that should not use your household's IP in public swarms. It is not a privacy shield against copyright enforcement, and we do not offer it as one: unauthorised sharing is not allowed on ProxyPanda, and our acceptable use policy leaves staying within the law to you. Lawful peer-to-peer traffic, on the other hand, is fine on our residential proxies and on dedicated ISP or datacenter IPs with no traffic cap. The torrent projects that address that worry recommend a VPN; proxy vs VPN explains why.

What will not go through the proxy

Read these first, because no checkbox changes them.

  • UDP stays out. Deluge uses libtorrent, which can relay DHT, UDP trackers and uTP over SOCKS5 using the protocol's UDP relay. We have not verified that relay on our gateways, so treat ProxyPanda's SOCKS5 as TCP only, as we do in HTTP vs SOCKS5. Expect DHT, UDP trackers and uTP not to work through us.
  • With an HTTP or SOCKS4 type it is the same, by design. libtorrent's source shows those UDP packets are refused rather than sent around the proxy, so they stop working instead of leaking.
  • No incoming connections. libtorrent's settings reference says a proxied session "will not accept incoming TCP connections, will not map ports with any gateway". You connect out to peers who accept connections, and that is all.
  • No encryption. The proxy adds none, and the SOCKS5 login crosses to it in plain text. Use the IP allowlist if you would rather not send a password at all.

Which type to choose in Deluge's list

Deluge's Proxy page lists seven types. They are quoted here from the GTK interface in Deluge's source.

Type Use it with ProxyPanda?
"None" Proxy off
"Socks4" No: we do not offer SOCKS4, and it has no password login or remote name lookups
"Socks5" Yes, if your address is on the IP allowlist
"Socks5 Auth" Yes, with your username and password
"HTTP" Trackers and web seeds; peers only where the proxy tunnels to their ports, which we have not confirmed for every port
"HTTP Auth" As HTTP, with a login
"I2P" Not a ProxyPanda product; leave it alone for this

The login is a separate type rather than a checkbox, which is easy to miss. In libtorrent, the engine underneath, plain SOCKS5 is the no-login type and SOCKS5 with a username and password is a different one, so pick the "Auth" variant whenever you want Deluge to log in.

The checkboxes, and the two that do less than they sound

Deluge's source lists five options on the same page, with these defaults:

  • "Proxy Hostnames", on: names are resolved at the proxy, not by your own resolver.
  • "Proxy Peers", on: peer connections go through the proxy.
  • "Proxy Trackers", on: tracker connections go through the proxy.
  • "Force Proxy Use", off. It maps to a libtorrent setting called force_proxy, which libtorrent deprecated in version 1.2, so on current builds it should add nothing. That is our reading of the source, not something we ran.
  • "Hide Client Identity", off. Its tooltip reads "Attempt to hide client identity and only use proxy for incoming connections." It maps to libtorrent's anonymous mode, which, per libtorrent's own documentation, stops the client sending its name and version and does not route traffic anywhere. Do not treat it as a stronger proxy setting.

So the defaults are already the ones you want. If you unticked "Proxy Peers" at some point, tick it again: without it, the proxy carries tracker traffic while every peer sees your address.

If Deluge runs as a daemon

Deluge is built as a daemon plus a client: the GTK window, the Web UI or the console can all connect to a daemon on the same machine or on a server elsewhere. In Deluge's source the proxy settings belong to the core's preferences, the part that runs in the daemon. So when you set them from a thin client on your laptop, they apply on the server where the daemon runs, and the traffic leaves from there.

That is convenient for a server with a fixed public address: add the server's IP to the allowlist, choose plain "Socks5", and no password needs to live on it. It also means checking the meter is a question about the server's traffic, not your laptop's.

Check the meter after the first torrent

Start with a known-good proxy. From the machine where the daemon runs:

curl -s -x socks5h://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org

Then note the service's traffic figure in the dashboard, let Deluge fetch something small and lawful, and compare. Figures in the dashboard update regularly rather than live, so give it a few minutes (where to find them).

  • If the dashboard moved by about what Deluge downloaded and uploaded, peers are going through the proxy.
  • If it barely moved, check the type is a SOCKS5 one and that "Proxy Peers" is ticked.

What seeding costs on a metered proxy

Deluge is a favourite for boxes that seed for weeks, and that is where a metered proxy needs thought. Each piece you upload to another peer crosses the proxy as well as each piece you download. How each direction counts on your plan is written under metering. Set an upload cap or a ratio at which seeding stops before you leave it alone. The proxy applies to the whole daemon, so torrents that do not need a separate address are better run with it off, or on another client. For a long-running client, a static ISP or datacenter IP keeps one steady address in front of trackers and peers. Choose a dedicated one with no traffic cap and weeks of seeding stop costing by the gigabyte, since it is billed per IP for its term; residential stays metered. Rates are on the pricing page.

Quick answers

Does Deluge proxy peers by default? Yes, once you choose a proxy type. "Proxy Peers" defaults to on.

How do I give Deluge a proxy username and password? Choose the "Socks5 Auth" type. Plain "Socks5" is the type for an allowlisted address with no login.

Does "Force Proxy Use" stop leaks? On current builds it should have no extra effect; the libtorrent setting behind it is deprecated.

Will DHT work through ProxyPanda? Expect not. We treat our SOCKS5 as TCP only, and DHT runs over UDP.

Next step

Deluge's current release is 2.2.0, and the project moves slowly, so if your Preferences page differs from what is described here, tell us in Discord and we will check it. For how Deluge compares with other clients, see which torrent clients work with SOCKS5.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord