The same proxy can speak several protocols: HTTP, HTTPS and SOCKS5. The address, login and password are the same; what differs is the traffic each one can carry and what outsiders can see on the way from you to the proxy. Here is how they differ, why Netrun offers only SOCKS5 and HTTPS, and which to pick for your task.
In short
- SOCKS5 is universal: it carries any connection, and almost every program and anti-detect browser understands it.
- HTTPS is for web traffic, and it is the only one that encrypts the connection to the proxy itself: your login, password and the sites you visit can't be seen on the network between you and the proxy.
- HTTP is also for web traffic, but without encryption to the proxy: the login and password travel across the network in plain text. That is why Netrun doesn't offer it.
HTTP proxies
An HTTP proxy understands the protocol websites speak — HTTP. When you open a plain http:// site, the proxy sees the whole request and response. For https:// sites the browser asks the proxy to open a tunnel (the CONNECT command), and the page content is encrypted between the browser and the website — the proxy can't see it.
The weak spot is the connection to the proxy itself. It isn't encrypted, so anyone who can see your traffic — the owner of a public Wi-Fi network, your provider — can see:
- your proxy login and password: they are sent in the
Proxy-Authorizationheader as Base64, which is an encoding, not encryption — anyone can decode it; - the addresses of the websites you open;
- the full content of plain
http://sites.
HTTPS proxies
An HTTPS proxy works just like an HTTP one, but the connection to it is wrapped in TLS — the same encryption that protects websites with a padlock in the address bar. Nobody between you and the proxy can see your login and password, the sites you visit or the content of the pages.
Another plus: the proxy, not your device, looks up the website's address in DNS. DNS queries don't leave your computer, and the proxy decides which of the website's addresses to connect to.
HTTPS proxies are supported by curl, Python (recent versions of the requests library) and Chromium-based browsers launched with proxy settings. Support in anti-detect browsers varies: if HTTPS is in the list of proxy types, choose it; if not, use SOCKS5.
SOCKS5
SOCKS5 works at a lower level and doesn't care what it carries. It simply connects your program to the server it needs and passes data both ways. That is why SOCKS5 works not only for browsers but also for messengers, email clients, games and any program with proxy settings.
SOCKS5 has no encryption to the proxy either: the login and password are sent openly, and content is protected only if it is encrypted by itself (as on https:// sites). On a trusted network that is fine; on public Wi-Fi, HTTPS is the better choice.
socks5:// vs socks5h://
SOCKS5 has one important subtlety: who turns the website's name into an IP address.
socks5://— your device resolves the name and hands the proxy a ready-made IP;socks5h://— your device hands the proxy the website's name, and the proxy finds the address itself.
For IPv6 proxies this matters a lot. If a website answers over both IPv4 and IPv6, your device may pick the IPv4 address — and an IPv6 proxy can't connect to it. With socks5h:// the proxy picks the site's IPv6 address itself. So in scripts (curl, Python) write socks5h://. Browsers and anti-detect browsers usually pass the website's name to the proxy on their own, so there is nothing to choose there.
Protocols compared
| HTTP | HTTPS | SOCKS5 | |
|---|---|---|---|
| What it carries | Web traffic | Web traffic | Any connection |
| Connection to the proxy encrypted | No | Yes | No |
| Login and password on the network | Visible | Hidden | Visible |
| Who resolves the website's address | The proxy | The proxy | Your device or the proxy (socks5h) |
| Software support | Almost everywhere | curl, Python, browsers, some anti-detect browsers | Almost everywhere |
| At Netrun | No | Yes | Yes |
The content of https:// websites is encrypted whichever protocol you use: the proxy sees where you connect, not what is inside.
Which to choose for your task
| Task | Protocol |
|---|---|
| Anti-detect browser (Dolphin Anty, AdsPower, Octo Browser and others) | SOCKS5; HTTPS if the browser supports it |
| Scripts and scrapers in curl, Python and the like | HTTPS or socks5h:// |
| Working from public Wi-Fi or someone else's network | HTTPS |
| Programs that don't run over the web: email, messengers, games | SOCKS5 |
How to connect: examples
A proxy line in the chosen protocol looks like this (the login and password are the same; each protocol has its own port — take it from the downloaded list):
https://login:pass@host:port
socks5://login:pass@host:port
Checking with curl — the command shows the IP that websites see:
curl -x https://login:pass@host:port https://api64.ipify.org
curl -x socks5h://login:pass@host:port https://api64.ipify.org
In Python with the requests library:
import requests
proxy = "https://login:pass@host:port" # or "socks5h://…" (needs pip install "requests[socks]")
r = requests.get("https://api64.ipify.org", proxies={"http": proxy, "https": proxy})
print(r.text)
If your software expects a different line format, convert the list with our proxy converter.
FAQ
Is an HTTPS proxy slower than SOCKS5?
Encryption adds a little time when the connection is set up but hardly affects download speed. You most likely won't notice the difference.
Can I change the protocol after buying?
Yes. You choose the protocol when you download the list, and you can download it again in another protocol at any time: in your account on the website ("NETRUN proxies" → the order) or in the Telegram bot ("My proxies" → "Download"). The login and password stay the same; the port changes.
Why doesn't Netrun offer plain HTTP?
Because everything an HTTP proxy can do, an HTTPS proxy can do too — with the connection to the proxy encrypted. There is no point sending logins and passwords in plain text when there is a secure alternative. If your software needs SOCKS5 or HTTPS, we have both.
You can choose the country and number of IPv6 proxies in our configurator, and the protocol when the list is issued.