Tutorial8 October 20266 min read

rTorrent SOCKS5 proxy: network.proxy.global.set, and the login caveat

rTorrent SOCKS5 proxy setup with network.proxy.global.set: what it proxies, what it switches off, and why we suggest an allowlisted address instead of a login.

An rTorrent SOCKS5 proxy is one line in .rtorrent.rc, available since rTorrent 0.16.16: network.proxy.global.set = "socks5h://HOST:PORT". With it, rTorrent sends its connections through the proxy and, per its own wiki, switches off UDP trackers, DHT and listening ports. Put your server's address on our IP allowlist rather than writing a login into that line: the current source drops the username and password for peer connections.

rTorrent is usually a server program, so this page is written for someone at a terminal on a box they control.

On a seedbox, do you need a proxy at all?

Often you do not. A rented seedbox or a server already has its own address, separate from your home connection, and its bandwidth is usually priced for heavy use. Adding a metered proxy in front of it means every gigabyte the box moves is paid for twice: once in the box's own allowance and once on the proxy.

A proxy fits when you need rTorrent to leave from an address other than the server's: a particular exit location, or a server whose own address you would rather keep out of a project's swarm. Keep it to content you can share. Distribution images, open-source releases, research datasets and Creative Commons collections are what rTorrent seeds best. Unauthorised sharing is not allowed on ProxyPanda, and our acceptable use policy makes staying within the law your responsibility. Peer-to-peer traffic for lawful content is fine on our residential proxies and on dedicated ISP or datacenter IPs with no traffic cap.

Check your version first

The proxy commands arrived in v0.16.16, released on 3 July 2026, with release notes that read: "new proxy support, using network.proxy.global.set and network.proxy.http.set, with http://, socks5:// and socks5h:// support". The current release is v0.16.25.

Distribution packages lag. When we installed rTorrent from Alpine Linux packages on 8 October 2026, the stable branch gave us 0.15.2 and even the edge branch 0.16.12, both older than the release that added proxy support. Check yours:

rtorrent -h | head -1

Below 0.16.16, these commands do not exist. The older network.http.proxy_address is deprecated.

The two proxy commands

Command What it does
network.proxy.global.set The proxy for rTorrent's connections, including peers, per the 0.16.16 notes: "support for socks5 for peer connections"
network.proxy.http.set "Sets HTTP proxy (overrides global)" for HTTP requests such as tracker announces; "Supports all native libcurl schemas"

The wiki lists three forms for the global proxy, shown here with our placeholders: http://HOST:PORT, socks5://USERNAME:PASSWORD@HOST:PORT and socks5h://USERNAME:PASSWORD@HOST:PORT. Prefer socks5h://, which hands hostnames to the proxy to resolve rather than looking them up on your server.

What switching it on turns off

rTorrent's wiki page "Proxy-Configuration" states it plainly: "UDP (trackers/dht) and listening ports are disabled." In practice:

  • UDP trackers and DHT stop. They are not sent around the proxy; they are switched off. That suits our SOCKS5, which you should treat as TCP only, since we have not verified a UDP relay on our gateways. HTTP vs SOCKS5 has the background.
  • No listening port. Other peers cannot connect in. rTorrent can still upload to the peers it connects out to, so seeding continues, with fewer peers.
  • Torrents need working HTTP trackers. A torrent that relies on UDP trackers or DHT will find no peers. Most distribution torrents list HTTP trackers, but check before you count on it.
  • Nothing is encrypted by the proxy. A SOCKS5 login, where one is sent, crosses the network in plain text.

The login caveat, and the way round it

The wiki documents a username and password inside the URL, and its own example writes user:pass@ in front of the proxy address. But rTorrent's source at tag v0.16.25 parses the user and password out of a socks5:// URL and then builds the SOCKS5 connection without passing them on. We read that in the code; we have not run it. If the code does what it appears to, an authenticated SOCKS5 proxy will refuse rTorrent's peer connections, while the same login may work in other tools.

Rather than depend on it, use the IP allowlist: add your server's address in the dashboard, and the proxy accepts its connections without a login. A server with a fixed address is exactly what the allowlist is for, and it keeps the password out of your config files too. Then:

network.proxy.global.set = "socks5h://HOST:PORT"

HOST and PORT come from your service page. On ISP and datacenter proxies, switch the proxy to SOCKS5 in the dashboard first and copy the port it shows.

Setting it, and changing it later

  1. Add the line above to ~/.rtorrent.rc.
  2. Restart rTorrent so the new setting applies to fresh connections.
  3. If you drive rTorrent over XML-RPC, both proxy commands are marked safe to call that way in rTorrent's source, so a script can change them at runtime.

Whether ruTorrent, the usual web front-end, shows these settings anywhere in its interface, we could not confirm. Set them in the config file and treat ruTorrent as a view onto the result.

Prove it from the server, then read the meter

First, from the same server, check the proxy answers and returns a different address:

curl -s -x socks5h://HOST:PORT https://api.ipify.org

Then read the meter against rTorrent's own totals:

  1. Note the service's traffic figure in the dashboard. How to see how much traffic is left shows where.
  2. Let rTorrent fetch a small, lawful torrent with HTTP trackers.
  3. After a few minutes, since dashboard figures update regularly rather than live, compare the movement with what rTorrent downloaded and uploaded.

If the two roughly agree, peers are going through the proxy. If rTorrent shows peers but the meter barely moves, something is connecting around it. If rTorrent shows no peers at all, check the torrent has HTTP trackers, and check the allowlist entry matches the server's real outgoing address.

Seeding around the clock on a metered proxy

rTorrent is built to seed all day, every day, and a metered proxy charges by the gigabyte. Uploading to other peers crosses the proxy as well as downloading does; how each direction counts on your plan is under metering. The global proxy covers every torrent in that rTorrent, so cap upload speed or stop torrents at a ratio, and run anything that does not need a separate address in an instance without the proxy. For a server, a dedicated ISP or datacenter IP with no traffic cap is the steadier fit and the cheaper one for round-the-clock seeding: it is billed per IP for its term, not by the gigabyte. Rates are on the pricing page.

Quick answers

How do I set a SOCKS5 proxy in rTorrent? network.proxy.global.set = "socks5h://HOST:PORT" in .rtorrent.rc, on version 0.16.16 or later.

Does rTorrent's proxy carry DHT? No. With a global proxy set, UDP trackers, DHT and listening ports are disabled.

Can I put my proxy username and password in the URL? The wiki documents it, but the v0.16.25 source appears not to pass them on for peer connections. Use the IP allowlist until that is tested.

Is network.http.proxy_address still the way? No. It is deprecated in favour of the two commands above.

Next step

If you test an authenticated SOCKS5 URL on a recent rTorrent and it works for peers, or does not, tell us in Discord and we will update this page with what you saw. For how other clients compare, see which torrent clients work with SOCKS5.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord