Short answers
What causes ERR_PROXY_CONNECTION_FAILED?
Chromium defines it as failure to create a connection to the proxy: either resolving its name or connecting a socket. A wrong address, closed port or inaccessible network route can fit that stage. The code alone does not identify which one occurred.
Is it the same as ERR_TUNNEL_CONNECTION_FAILED?
No. ERR_TUNNEL_CONNECTION_FAILED refers to establishing a tunnel through the proxy. An HTTP CONNECT response such as 407, 403 or 502 belongs to that later stage. Record the actual response before choosing a fix.
What is ERR_MANDATORY_PROXY_CONFIGURATION_FAILED?
Chromium uses it when a mandatory proxy configuration cannot be used: currently, a required PAC script could not be fetched, parsed or executed. Check the script and whoever supplied it rather than repeatedly editing a manual proxy password.
Should I disable the proxy?
Remove a stale proxy that you added to your own unmanaged device if you no longer need it. For a required school or work configuration, ask the administrator to repair the route. Record the old settings and exact error before making a change.
These definitions and desktop settings labels were checked against Chromium’s current main-branch source on 4 October 2026. This is a documentation-checked diagnostic, not a recorded test in a specific Chrome release. Record your installed version from chrome://version; labels and configuration sources can differ.
Read the code before changing settings
| Message or code | Start here |
|---|---|
ERR_PROXY_CONNECTION_FAILED | The configured proxy’s hostname, listener port and network route. |
ERR_MANDATORY_PROXY_CONFIGURATION_FAILED | The required PAC URL or script; see the automatic-configuration section below. |
ERR_TUNNEL_CONNECTION_FAILED | The CONNECT tunnel diagnostic, including the response from the proxy. |
407 Proxy Authentication Required or a proxy sign-in prompt | The 407 guide or prompt guide. |
A page saying only Unable to connect to the proxy server gives less evidence than the error code. Keep the code printed with it, the failed URL’s hostname and the time. Chromium’s network error definitions distinguish proxy connection, tunnel and mandatory-configuration failures.
Find the proxy Chrome is actually using
- Open
chrome://settings/system. When system settings supply the route, the control is labelledOpen your computer's proxy settings. - If an extension supplies the settings, inspect that extension’s active proxy entry. Make sure you are checking the Chrome profile that failed.
- If an administrator controls the route, inspect
chrome://policyand send the proxy policy details to the administrator. Keep required rules in place. - If you launch Chrome from a shortcut, test runner or script, inspect any proxy launch options there. A system setting change may not alter that launch configuration.
On Windows 10 or 11, the system pane is Settings > Network & internet > Proxy. On macOS Tahoe 26, select the active network service in System Settings > Network, then Details > Proxies. Record whether the route uses a manual server, PAC URL or automatic discovery. The proxy settings guide explains those modes.
The Chromium settings source documents the system control and indicators for extension or administrator control. Its proxy documentation identifies policy, launch options, extensions and system settings as possible configuration sources.
Check the host and port together
- Copy the gateway hostname again from the supplied connection details. Keep a URL scheme or credential URL out of a separate hostname field.
- Compare the protocol and port as a pair. For Portproof’s authenticated HTTP route, use host gw.portproof.org and port 7000 from the connection builder.
- If the proxy runs on your computer, confirm that its local process is running and listening on the configured port. An old local proxy entry can remain after the app stops.
- If the server is on an organisation’s network, check whether the required network or VPN connection is available. Ask the administrator about permitted access to that host and port.
For an authenticated Portproof connection in Chrome, choose the HTTP endpoint. Chromium does not support SOCKS5 username/password authentication. An HTTPS destination can use an HTTP proxy through CONNECT; the destination scheme is not a reason to replace the gateway protocol or port.
Compare one explicit curl request
If you intentionally use Portproof, run this bounded check in an interactive POSIX terminal. Replace the username label with the complete generated username. curl asks for the proxy password; do not append it to the command. It makes one small request to the echo endpoint with certificate verification enabled.
curl_status=0
curl --disable --silent --show-error \
--proxy 'http://gw.portproof.org:7000' \
--proxy-user 'YOUR_FULL_PROXY_USERNAME' \
--noproxy '' \
--connect-timeout 5 --max-time 15 \
--output /dev/null \
--write-out 'connect_status=%{http_connect} target_status=%{response_code}\n' \
'https://api.portproof.org/v1/echo-ip' || curl_status=$?
printf 'curl_exit=%s\n' "$curl_status"This uses the diagnostic pattern in the existing curl guide; no new live-gateway or browser test is claimed here. --disable comes first to skip a default curl configuration file, and the explicit proxy with an empty exclusion list fixes the route for this check. Windows PowerShell needs curl.exe and adapted shell syntax. curl option reference.
| Observed result | Next step |
|---|---|
| Proxy name cannot resolve; connection is refused or times out | Use connection refused and timeouts. Keep the exact message as well as the exit number. |
connect_status=407 | The gateway answered. Follow the 407 guide for authentication and gateway-code checks. |
| CONNECT returns 403, 502 or 503 | Follow the CONNECT guide. Distinguish the tunnel response from a later website response. |
| CONNECT succeeds and the expected endpoint responds | Compare Chrome’s selected gateway, profile and authentication handling with this explicit request. |
| A certificate validation error | Check the destination hostname, clock and trusted CA configuration. Keep TLS verification enabled. |
A curl success confirms that curl reached the specified gateway for that request. It does not prove Chrome selected it. Conversely, curl against a manual host does not evaluate Chrome’s PAC script. For version-specific curl numbers and measured local examples, use the linked refusal and CONNECT guides.
When a required PAC configuration fails
For ERR_MANDATORY_PROXY_CONFIGURATION_FAILED, record the configured PAC URL and configuration source. Ask its owner to check availability, syntax and execution. Chrome’s PAC API can mark a script mandatory, preventing direct fallback when the script is invalid. Chrome PAC reference.
A script which cannot be obtained or evaluated is a different case from a valid script which selects an unreachable proxy. Use the exact error to retain that distinction. Do not clear a required script or add a direct fallback merely to suppress the message; that changes the intended route instead of repairing the configuration.
Keep a useful report
Record the UTC time, Chrome version, exact error code, configuration source, proxy host and port without credentials, destination hostname and the curl result if tested. If an authorised comparison from another network works, report that difference. Share passwords, API keys and credential URLs with neither a screenshot nor a public bug report.
If those details do not explain the route, Chromium’s NetLog instructions describe a capture with chrome://net-export. Use the default privacy mode, reproduce only the small failing request, then stop. Review the capture before sharing; sensitive URLs can still be present.
Sources and scope
Primary references checked on 4 October 2026: Chromium network errors, proxy behaviour, Chrome proxy API and curl documentation. Chromium main-branch definitions are not a verification of every installed Chrome release.
What is not allowed
Test only endpoints you are permitted to access and follow the acceptable-use policy.
Read next
Proxy connection refused or timing out
Separate a refused or unreachable gateway from a timeout, a wrong port and an answered tunnel, using curl’s code and message.
Read the guide
Proxy errors: find the cause and next check
Match the exact error to its failing stage and follow one targeted check before changing credentials or retrying a workload.
Read the guide