Short answers
Which proxy error should I investigate first?
Use the most specific message you have: a browser code, curl’s complete error line, a Python exception with its underlying cause, or a gateway code. Identify whether the client reached the proxy before changing authentication or the destination request.
Is 407 the same as a connection refusal?
No. HTTP 407 is a proxy authentication response. A refused connection can happen before an HTTP response is received. The 407 and connection-refused guides below follow those stages separately.
What if curl works and my app does not?
Compare the same gateway, destination and credentials in the actual application process. It may use different environment variables, exclusions, transport settings or saved credentials. Start with the curl-versus-app guide, then use the guide for your client.
Browser messages and sign-in prompts
| What you see | Focused guide |
|---|---|
The proxy requires a username and password | Identify the proxy and choose its credentials. |
Firefox: The proxy server is refusing connections | Check the selected proxy’s reachability. |
Chrome: ERR_PROXY_CONNECTION_FAILED | Check proxy name resolution, host, port and route. |
Chrome: ERR_MANDATORY_PROXY_CONFIGURATION_FAILED | Check the required PAC configuration. |
Chrome: ERR_TUNNEL_CONNECTION_FAILED | Separate CONNECT failure from a website response. |
| A proxy setting you do not recognise | Understand manual, PAC and automatic settings. |
curl messages and exit codes
Match the message as well as the number. Error text can include the proxy or the destination hostname, and curl releases can assign different exit codes to a failed CONNECT. The linked guides include their recorded versions and local fixture scope.
| What you see | Focused guide |
|---|---|
Could not resolve proxy or Could not resolve host naming the gateway | Check the gateway hostname and DNS. |
Failed to connect / Couldn't connect to server | Check a refused port and network reachability. |
Timeout was reached, a connection timeout or an unanswered proxy handshake | Distinguish connection and handshake timeouts. |
CONNECT tunnel failed, response 407 | Check proxy authentication and balance. |
CONNECT tunnel failed, response 403, 502 or 503 | Read the CONNECT status and gateway evidence. |
User was rejected by the SOCKS5 server | Check SOCKS5 authentication and the matching port. |
SSL certificate problem | Check the certificate stage with verification enabled. |
| No clear error, but the route or exit IP is unexpected | Run one explicit proxy check. |
Python, Node.js and app failures
| Client and message | Focused guide |
|---|---|
Requests: ProxyError, ConnectionError, ConnectTimeout or ReadTimeout | Requests proxy exception checks. |
Requests: SSLError | Requests certificate and environment checks. |
HTTPX: ProxyError, ConnectError or HTTPStatusError | HTTPX transport and response checks. |
aiohttp: ClientProxyConnectionError, ClientConnectorDNSError or ConnectionTimeoutError | aiohttp connection diagnostics. |
aiohttp: ClientHttpProxyError or ClientConnectorCertificateError | aiohttp tunnel and certificate checks. |
Node.js: TypeError: fetch failed | Inspect the underlying cause and dispatcher. |
| The proxy works in curl but fails in the app | Compare process settings and proxy exclusions. |
An exception class is a starting point. Keep its cause and response status when available. A returned website status is different from a client failing before it receives that response; follow the linked client guide to identify the stage.
Portproof gateway codes
Use these only when the gateway actually reports the detailed code. A bare 407 or 502 cannot establish the corresponding cause by itself. The setup reference lists the documented gateway responses.
| Status and code | Focused next step |
|---|---|
407 · E_AUTH_INVALID | Check the full generated username and proxy password. |
407 · E_CAP_EXCEEDED | Check remaining GB and traffic validity. |
400 · E_USERNAME_PARSE | Rebuild the username with accepted tokens. |
429 · E_RATE_LIMITED_CONN | Review parallel connection limits and retry guidance. |
429 · E_SESSION_LIMIT | Review named sessions and intended reuse. |
502 · E_NO_STOCK_COUNTRY | Check current availability for the chosen pool and country. |
If the message is not listed
Start with the curl check against a small authorised endpoint. Record the UTC time, client version, proxy scheme, host and port without credentials, exact message, CONNECT status and destination status when available. Keep passwords, API keys and credential-bearing URLs out of shared logs. That report helps establish which guide or support check applies.
Sources and scope
References checked on 4 October 2026: Chromium error definitions, Firefox error strings, curl error reference, Requests exceptions, HTTPX exceptions, aiohttp exceptions and Undici’s fetch error handling. This directory adds navigation; test evidence remains in each linked guide.
What is not allowed
Use diagnostics only for permitted services and follow the acceptable-use policy.
Read next
Proxy connection refused or timing out
Separate a refused or unreachable gateway from a timeout, a wrong port and an answered tunnel, using curl’s code and message.
Read the guide
Fix CONNECT tunnel failed: 403, 502 and 503
Read the proxy and destination statuses separately, then choose the next check for 403, 407, 502 or 503.
Read the guide