Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use curl -x (or --proxy) to send a request through an HTTP, HTTPS, or SOCKS proxy. Add -U for proxy credentials, choose --socks5 when DNS should resolve on your machine, and choose --socks5-hostname (or socks5h://) when the proxy should resolve the destination. Environment variables provide defaults, while --noproxy bypasses a proxy for selected hosts.

This guide covers command syntax, authentication, DNS behavior, tunneling, environment configuration, secret handling, troubleshooting, and a ready-to-run alternative for automated website captures.

Choose the proxy option that matches your connection

The proxy URL tells curl where to connect and which protocol to speak. If you omit a scheme, curl treats the proxy as HTTP.

Use case Command What happens
HTTP proxy curl -x http://proxy.example:8080 https://example.com curl connects to an HTTP proxy. For an HTTPS destination it normally requests a CONNECT tunnel.
HTTPS proxy curl -x https://proxy.example:8443 https://example.com curl encrypts its connection to the proxy itself, then accesses the destination through it.
SOCKS5, local DNS curl --socks5 proxy.example:1080 https://example.com Your machine resolves example.com; the proxy receives the resulting address.
SOCKS5, proxy DNS curl --socks5-hostname proxy.example:1080 https://example.com The proxy resolves example.com. The equivalent URL form is socks5h://proxy.example:1080.

--proxy and its short form -x accept http://, https://, socks4://, socks4a://, socks5://, and socks5h://. The proxy URL forms documented by curl use port 1080 when a SOCKS proxy port is omitted; specify the port explicitly to avoid ambiguity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.

Send a request through an HTTP or HTTPS proxy

Basic proxy request

curl -x http://proxy.example:8080 https://example.com

The explicit -x option takes precedence over proxy environment variables. Use the long form when documenting scripts for people who may not know curl’s short options:

curl --proxy https://proxy.example:8443 https://example.com

Request an HTTP CONNECT tunnel

For an HTTP proxy and an HTTPS destination, curl commonly uses the HTTP CONNECT method. If you need to request tunneling explicitly, add --proxytunnel:

curl --proxy http://proxy.example:8080 --proxytunnel https://example.com

CONNECT establishes a tunnel through the HTTP proxy; it does not turn the proxy into a SOCKS server. Whether CONNECT is allowed is controlled by the proxy administrator.

Chain a SOCKS pre-proxy with an HTTP proxy

--preproxy lets curl reach an HTTP or HTTPS proxy through a SOCKS proxy:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --preproxy socks5h://socks.example:1080 --proxy http://proxy.example:8080 https://example.com

Use this only when your network requires that two-stage path. The destination request still follows the behavior of the final HTTP or HTTPS proxy.

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.

Authenticate to the proxy

Username and password

Proxy credentials belong in --proxy-user (short form -U), not in the remote-server-only authentication options:

curl --proxy http://proxy.example:8080 
  --proxy-user 'user:password' 
  https://example.com

If the password is omitted, curl can prompt for it interactively. This avoids putting the password directly in the command text:

curl --proxy http://proxy.example:8080 --proxy-user 'user' https://example.com

Quote the value whenever it contains shell characters such as !, $, spaces, or a backslash. URL-encoding credentials inside a proxy URL is possible, but --proxy-user is clearer and avoids confusing URL parsing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Select the HTTP proxy authentication method

HTTP proxies can challenge with several methods. Use the method-specific flag when your administrator tells you which one is required:

  • --proxy-basic — HTTP Basic authentication (curl’s default HTTP proxy method).
  • --proxy-digest — HTTP Digest authentication.
  • --proxy-ntlm — NTLM authentication.
  • --proxy-negotiate — Negotiate/SPNEGO authentication when curl and the environment support it.
  • --proxy-anyauth — let curl discover and select a method supported by the proxy.
curl -x http://proxy.example:8080 
  -U 'user:password' 
  --proxy-digest 
  https://example.com

--proxy-anyauth may require an extra request/response round trip while curl discovers the acceptable method. For predictable automation, selecting the known method is preferable.

Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

SOCKS authentication

SOCKS5 username/password authentication can be selected with --socks5-basic. Environments that provide GSS-API can use --socks5-gssapi:

curl --socks5 proxy.example:1080 
  --proxy-user 'user:password' 
  --socks5-basic 
  https://example.com

SOCKS4 and SOCKS4a have different protocol capabilities; use the proxy type your server actually provides.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand SOCKS DNS resolution

--socks5: resolve locally

With --socks5 proxy:port, curl resolves the destination hostname locally before opening the SOCKS connection. This is useful when your local resolver is authoritative or when the proxy cannot resolve internal names. It also means the DNS query does not go through the SOCKS proxy.

--socks5-hostname and socks5h://: resolve through the proxy

With --socks5-hostname proxy:port, curl sends the hostname to the proxy and asks it to resolve the name. Use this when local DNS would leak a name, cannot reach a private DNS zone, or would return a different address than the proxy’s network.

curl --socks5-hostname proxy.example:1080 https://private.example
curl -x socks5h://proxy.example:1080 https://private.example

SOCKS4 versus SOCKS4a

--socks4 resolves locally and sends the address to the proxy. --socks4a asks the proxy to resolve the hostname. Pick the variant using the same local-versus-proxy DNS decision as SOCKS5.

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft

Set proxy defaults with environment variables

Environment variables are convenient for shells, CI jobs, and applications that invoke curl repeatedly:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • http_proxy — default proxy for HTTP URLs.
  • HTTPS_PROXY — default proxy for HTTPS URLs.
  • FTP_PROXY — default proxy for FTP URLs.
  • ALL_PROXY — general fallback proxy.
  • NO_PROXY — hosts and domains that should not use a proxy.
export http_proxy=http://proxy.example:8080
export HTTPS_PROXY=http://proxy.example:8080
export ALL_PROXY=socks5h://proxy.example:1080
export NO_PROXY=localhost,127.0.0.1,.internal.example

curl https://example.com

A leading dot in NO_PROXY, such as .internal.example, matches that domain and its subdomains. Environment variable names are case-sensitive on many Unix-like systems; set the spelling expected by your environment. An explicit -x/--proxy on the command line overrides the environment defaults.

Bypass the proxy for one command

Use --noproxy when the exception should apply only to one invocation:

curl --noproxy 'localhost,127.0.0.1,.internal.example' 
  -x http://proxy.example:8080 
  https://example.com

To bypass proxying for every host in that command, use --noproxy '*'. Check inherited NO_PROXY values if a request unexpectedly avoids the proxy.

Protect proxy credentials

Command-line arguments can be visible to other users through process-listing tools. Although curl may briefly hide an option argument on systems where that is supported, do not treat the command line as a secret store.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
  • Prompt interactively by supplying only the username with --proxy-user.
  • Use a protected configuration file or your CI platform’s secret mechanism for unattended jobs.
  • Restrict file permissions and avoid committing proxy URLs containing credentials to source control.
  • Do not paste credentials into verbose logs, support tickets, or shell history.

When a proxy password contains characters meaningful to your shell, quote it or provide it through the protected mechanism rather than trying to debug shell expansion.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Diagnose failures with verbose output

Add -v to inspect proxy selection, the CONNECT exchange, TLS negotiation, and authentication challenges:

curl -v -x http://proxy.example:8080 https://example.com

Verbose output can include headers and sensitive values. Review it before sharing. Use -I for a headers-only test when the server supports HEAD, or use --trace-time with a protected trace file when timing details are needed.

Common errors and fixes

Symptom Likely cause Fix
Unsupported proxy scheme The URL uses a scheme curl does not recognize or a typo in the scheme. Use one of http://, https://, socks4://, socks4a://, socks5://, or socks5h://.
Could not resolve proxy The proxy hostname or local DNS is wrong. Verify the proxy name, port, and local resolver; test with -v.
407 Proxy Authentication Required The proxy requires credentials or a different HTTP authentication method. Add -U and select --proxy-basic, --proxy-digest, --proxy-ntlm, --proxy-negotiate, or --proxy-anyauth as appropriate.
SOCKS connection succeeds but hostname fails DNS is happening on the wrong side of the proxy. Switch between --socks5 and --socks5-hostname (or socks5h://).
HTTPS request rejected at CONNECT The HTTP proxy disallows tunneling to that destination or port. Ask the proxy administrator to permit CONNECT, or use a permitted proxy/protocol.
Request unexpectedly goes direct NO_PROXY or --noproxy matches the host. Inspect and adjust the bypass list, then retest with -v.
Authentication loops or adds delay Automatic method discovery is negotiating repeatedly. Replace --proxy-anyauth with the known method-specific flag.

Performance, reliability, and billing considerations

A proxy adds at least one network hop and, for HTTP proxies serving HTTPS destinations, a CONNECT negotiation. SOCKS proxy-side DNS can avoid an unreachable local resolver but depends on the proxy’s DNS service. Reuse a single curl process for multiple URLs when possible, and keep proxy settings in a controlled environment rather than rebuilding them inconsistently per request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For scripts, set a finite timeout and capture the exit status. A successful TCP connection to the proxy does not prove that the destination loaded; inspect the final HTTP status and curl’s error code. Retry only idempotent requests and use backoff so a failing proxy is not overloaded.

Or skip the browser setup

If your goal is to obtain a clean screenshot of a website rather than manually browse it through a proxy, ScreenshotNeo provides a single HTTP request. Its API accepts options for viewport, device, full-page capture, CSS selectors, JavaScript, waits, headers, cookies, user agents, geolocation, timezone, blocking rules, resizing, caching, PDFs, bulk jobs, and more.

Basic cURL call (see the ScreenshotNeo documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners as a visitor, then removes more than 60 known consent platforms along with newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server includes take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick decision checklist

  • Use -x http://... for a standard HTTP proxy and -x https://... when the proxy connection itself must use TLS.
  • Use --proxy-user for proxy credentials and select the authentication method that the proxy advertises.
  • Choose --socks5 for local DNS or --socks5-hostname/socks5h:// for proxy-side DNS.
  • Use environment variables for defaults and --noproxy for a one-command exception.
  • Run with -v while diagnosing, but redact credentials and sensitive headers before sharing logs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.