Tutorial8 October 20269 min read

qBittorrent proxy settings: the two boxes that start switched off

qBittorrent proxy settings for SOCKS5: where the fields are, the two boxes that are off by default, what still goes direct, and how to check the meter.

qBittorrent proxy settings live under Tools > Options... > Connection, in the group called "Proxy Server". Pick SOCKS5, enter the host, port and login, then tick two boxes that start switched off: "Use proxy for BitTorrent purposes" and, inside it, "Use proxy for peer connections". Without both, the proxy carries little or none of your torrent traffic.

That is the short answer. The longer one starts with a question worth asking first, because a metered proxy costs money by the gigabyte and a torrent can move a lot of them.

Do you need a proxy for this download at all?

Often not. If you want a Linux image, a BSD release or a dataset that its publisher also offers over HTTP, the plain mirror download is simpler and puts nothing on a metered proxy. BitTorrent is a fine way to fetch those files, and it is fine without a proxy too.

A proxy earns its place when you want one application, and only that one, to leave from a different address: a test box that should not show your office IP in a swarm for your own project's release, or a client you want on a fixed exit while the rest of the machine stays on your normal connection.

If your worry is privacy from everyone who watches public swarms, qBittorrent's own wiki points elsewhere: "If you are concerned about legal authorities and copyright trouble, for example, consider using a VPN instead (or in addition to it)." We agree with it. Proxy vs VPN sets out the difference.

Whatever you download, keep it to files you have the right to share: open-source releases, Internet Archive and Creative Commons items, research data, game and software patches published over BitTorrent. Sharing anything else is not allowed on ProxyPanda, and our acceptable use policy makes staying within the law your responsibility. Peer-to-peer traffic itself is fine with us: lawful torrents can run on our residential proxies and on dedicated ISP or datacenter IPs with no traffic cap.

What a SOCKS5 proxy will and will not carry for qBittorrent

Read this before the setup steps, because it decides what you can expect.

  • Only TCP, on our side. SOCKS5 as a standard can relay UDP, and qBittorrent's engine, libtorrent, will try. We have not verified a UDP relay on our gateways, so treat SOCKS5 on ProxyPanda as TCP only, as we say in HTTP vs SOCKS5. DHT, UDP trackers and uTP use UDP, so expect them not to work through our proxy. HTTP trackers and TCP peer connections are what it will carry.
  • An HTTP proxy is worse. It cannot carry UDP at all. libtorrent's source shows that with an HTTP or SOCKS4 proxy, those UDP packets are refused rather than sent around the proxy, so they stop working instead of leaking.
  • No incoming connections. libtorrent's settings reference says a proxied session "will not accept incoming TCP connections, will not map ports with any gateway". Port forwarding on your router does nothing for proxied peers, and you will connect to fewer of them.
  • No encryption. A proxy relays bytes. The SOCKS5 login itself crosses the network in plain text.
  • Two directions of traffic. You download pieces, and while the torrent seeds you upload them to other peers. Both cross the proxy. How each direction counts on your plan is set out under metering; read it before you leave anything seeding.

Set it up, step by step

The labels below are quoted from qBittorrent's source at the release-5.2.4 tag, the current release on the day we wrote this. The same page exists in the Web UI of qbittorrent-nox.

  1. Open Tools > Options... and choose Connection.
  2. In Proxy Server, set the type to SOCKS5. The list offers "(None)", "SOCKS4", "SOCKS5" and "HTTP".
  3. Enter the host and port from your service page in the dashboard. On ISP and datacenter proxies, switch the proxy to SOCKS5 there first and copy the port again, since it can differ by protocol.
  4. Turn on authentication and enter your username and password. qBittorrent only offers a login for SOCKS5 and HTTP.
  5. Check that "Perform hostname lookup via proxy" is ticked, so names are resolved at the proxy rather than by your own resolver. It was already on in our fresh install.
  6. Tick "Use proxy for BitTorrent purposes".
  7. Inside it, tick "Use proxy for peer connections". Its tooltip says what happens if you skip it: "Otherwise, the proxy server is only used for tracker connections".
  8. Leave "Use proxy for RSS purposes" and "Use proxy for general purposes" as you prefer. The second, per its tooltip, sends "Search engine, software updates or anything else" through the proxy as well, and that is traffic on the meter too.
  9. Apply, then quit and reopen qBittorrent. In one of our runs, described below, ticking the BitTorrent box while the client was running did not move the tracker onto the proxy until after a restart.

If your address is on the IP allowlist, you can leave authentication off. Otherwise a missing login shows up as connection failures rather than a clear message; fixing a 407 covers the HTTP side of that.

Why both boxes start switched off, and what we saw

This is the part that catches people. In qBittorrent's source, Network/Proxy/Profiles/BitTorrent is read with no default, so it comes up false, and ProxyPeerConnections defaults to false outright.

We ran it rather than take the source's word for it. On 8 October 2026 we installed qbittorrent-nox 5.2.4 with libtorrent 2.1.0 from Alpine Linux's packages in a container, started it with no settings file, and confirmed both values came up false. We pointed it at a small SOCKS5 test server of our own that logs every request, relays TCP and refuses UDP, which is how we ask you to treat our gateways. Then we added Debian 13.7.0's netinst torrent at each step and watched for about 20 seconds:

What you set Through the proxy Straight from our own address
Host and port only Nothing Every peer connection, about 59 over TCP, plus about 51,000 UDP packets
Plus "Use proxy for BitTorrent purposes" The tracker announce About 55 peer connections over TCP, plus about 37,000 UDP packets
Plus "Use proxy for peer connections" 122 connections to 120 different addresses, peers among them One TCP connection and no UDP packets

The middle row looks finished in the dialog. It is not: every peer still saw our real address, and UDP traffic, the kind uTP and DHT use, left directly as well. In the last row, qBittorrent asked our test server once for a UDP relay, was refused, and sent no UDP around the proxy. The download still finished, over TCP. For the middle row we quit and reopened qBittorrent after ticking the box; in an earlier run, ticking it without a restart, our test proxy saw no tracker connection at all.

One more wrinkle from the source: when qBittorrent converts a settings file from an older version, an upgrade step stores "Use proxy for BitTorrent purposes" as on. We saw that too, so on an upgraded install the outer box may already be ticked. "Use proxy for peer connections" was off in every case.

If you prefer to check the config file, the keys the source reads include Network\Proxy\Profiles\BitTorrent and BitTorrent\Session\ProxyPeerConnections. If either is missing or false, peers are going direct.

SOCKS5, HTTP or SOCKS4?

Choose SOCKS5. It carries peer connections without needing the proxy to open tunnels to arbitrary ports. HTTP works for trackers and web seeds, and for peers only where the proxy allows tunnels to their ports, which we have not confirmed for every port on our HTTP proxies. SOCKS4 is the weakest: picking it disables hostname lookup, RSS and general proxying, and qBittorrent warns "Some functions are unavailable with the chosen proxy type!"

Anonymous mode is not a proxy

Tools > Options > BitTorrent > Privacy has "Enable anonymous mode", with the tooltip "Enable when using a proxy or a VPN connection". It stops the client announcing its name and version to trackers and peers. It routes nothing anywhere. qBittorrent's wiki says it "doesn't provide strong privacy guarantees on its own". Turn it on if you like, but do not count it as protection.

Check that it worked, then check the meter

First, prove the proxy itself answers, from the same machine:

curl -s -x socks5h://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org

It should print an address that is not yours. Then test the client on something small and lawful, such as a minimal network-install image from a Linux distribution or a short Creative Commons film from the Internet Archive.

Now the meter. Note your traffic figure in the dashboard before you start, let the torrent run, then compare how far the figure moved with what qBittorrent says it downloaded and uploaded. Dashboard figures update regularly rather than live, so give it a few minutes; how to see how much traffic is left shows where to look.

  • The meter moved roughly in step with the client: peers are going through the proxy.
  • The meter barely moved while the client downloaded hundreds of megabytes: peers are direct. Go back to the two boxes.
  • The meter moved a little more than the client's figure: normal. Protocol messages and discarded pieces are traffic too.

How to check your proxy provider's meter goes deeper if the numbers still disagree.

Keeping the cost down

A 4 GB image downloaded through a proxied qBittorrent moves at least 4 GB in, and seeding it back to a ratio of 1.0 moves another 4 GB out. Set an upload limit or a ratio at which seeding stops. The proxy applies to the whole client, so switch it off when you run torrents that do not need a separate address. A static ISP or datacenter IP suits a client better than a rotating exit, because trackers and peers see one steady address. For heavy seeding, pick a dedicated one with no traffic cap: it is billed per IP for its term, so the gigabytes you seed do not add to the bill. In the dashboard, such an IP's card says its bandwidth never runs out (how to tell). Residential stays metered by the gigabyte. Prices are on the pricing page.

Quick answers

Does qBittorrent proxy peers by default? No. Both "Use proxy for BitTorrent purposes" and "Use proxy for peer connections" start off.

Will DHT work through a ProxyPanda SOCKS5 proxy? Expect not. We treat our SOCKS5 as TCP only, and DHT is UDP.

Is there still a "disable connections not supported by proxies" option? No. qBittorrent's wiki says it is "Always enabled in qBittorrent 4.2 and above", and the option was removed.

Does the proxy encrypt my torrent traffic? No. A proxy changes the address peers see. It does not encrypt.

Next step

If you are not sure a proxy is the right tool for your download, ask in Discord before you top up; a plain answer costs nothing. Other clients handle all this differently, and which torrent clients work with SOCKS5 compares them side by side.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord