Check your connection

Pressing the button sends three requests from your browser: to our API at api.proxypanda.io, which returns the IP address your request arrives from, a short list of proxy-revealing headers and your user agent; to ipapi.is, with that address, to look up the network it belongs to; and to Google’s public STUN server, which tells your browser the address it sees, for the WebRTC check. We don’t store the result. Privacy policy

What a website sees

Nothing is checked until you press the button.

Reading the result

What each check tells you

Any website can check these four things about a visitor. When you test a proxy, they decide whether it hides what you meant it to hide.

  • Exit IP

    The address our server saw the request come from, the same one any website sees. Through a proxy, it should be the proxy’s exit IP. If it is your own address, the traffic is not going through the proxy.

  • Network type

    Which network announces the address (its ASN), and who holds the address block. The lookup this page uses usually comes back without a network type, and then the type shown is a guess from the network’s number and name, labelled as one. Datacenter proxies sit in hosting ranges, which is expected. Residential and ISP proxies should sit on internet providers’ networks, and a run of hosting results on a line sold as residential is the classic sign of a relabelled pool.

  • WebRTC leak

    WebRTC lets a page ask a STUN server which address your browser comes from. By default, browsers send that request directly rather than through an HTTP proxy, so a page can learn an address the proxy was meant to hide. Local network addresses are hidden behind random .local names, so only public addresses count here. An address of the other IP version is usually your connection’s second address, normal on a dual-stack connection, though it can still give you away if your proxy carries only one version.

  • Proxy headers

    Some proxies add headers such as Via, Forwarded and X-Forwarded-For to plain HTTP requests, and transparent proxies put your own address in them. Over HTTPS a proxy cannot add them, so on this page they only show up behind a proxy that decrypts HTTPS, or when your own software sends them.

Check a proxy

How to check a proxy in your browser

  1. Point your browser at the proxy. Firefox has its own connection settings; Chrome and Edge use the system settings or an extension.
  2. Open this page and press Check my connection.
  3. Compare the exit IP and its network with what you ordered.
  4. Read the WebRTC line. Another address of the same IP version as your exit IP is one a site can see past the proxy. An address of the other IP version is normal on a dual-stack connection, but can still give you away if your proxy carries only one version.
  5. Switch the browser back to a direct connection when you are done.

From a terminal

Check a proxy from the command line

Scripts and servers have no browser, so there is no WebRTC to leak, and the exit IP is what matters. Send one request through the proxy to our echo endpoint:

terminal
curl -sx http://USER:PASS@IP:PORT https://api.proxypanda.io/tools/echo

Replace USER and PASS with the username and password on your service page, and IP and PORT with its host and port.

The reply is JSON. Its ip field is the address the request arrived from, which should be the proxy’s exit IP. The request is HTTPS, so the proxy only relays an encrypted tunnel and the headers field normally comes back empty. Add | jq to the end to make the reply easier to read.

Got a result you cannot read?

Paste it in Discord and we will help you read it, including when the problem is one of our IPs. Leave out any address you would rather keep private.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord