Skip to content
Troubleshooting

ERR_PROXY_CONNECTION_FAILED and ERR_TUNNEL_CONNECTION_FAILED: What Each Means and How to Fix It

ERR_PROXY_CONNECTION_FAILED means Chrome could not reach the proxy at all: the address did not resolve, the port was closed, or something on your machine blocked the connection. ERR_TUNNEL_CONNECTION_FAILED means Chrome did reach the proxy, but the proxy refused to open the HTTPS tunnel — usually because of missing credentials, a blocked destination, or an upstream it could not reach. They look alike on screen and need opposite fixes, so the first step is always to identify which one you have.

seamless Team10 min readSeptember 28, 2026
  • troubleshooting
  • chrome
  • proxy errors
  • windows
A routing line from a client block that stops short of the relay node, leaving a crimson gap before the dark onward path

Chrome's error page for the first one reads *There is something wrong with the proxy server, or the address is incorrect*. The second often lands on a generic *This site can't be reached* screen with the code at the bottom. Either way, the code is the useful part.

Which error you have, and what it tells you

ErrorCodeWhat failedWhere to look
ERR_PROXY_CONNECTION_FAILED−130No connection to the proxy at allHost, port, firewall, system proxy settings
ERR_TUNNEL_CONNECTION_FAILED−111Proxy reached, CONNECT tunnel refusedCredentials, whitelist, blocked port or target
ERR_PROXY_CERTIFICATE_INVALID−136The HTTPS proxy's own certificate is invalidProxy scheme — you probably meant http://
ERR_NO_SUPPORTED_PROXIES−336No proxy in the list uses a scheme Chrome supportsTypo in the scheme, e.g. socks:// with auth
ERR_MANDATORY_PROXY_CONFIGURATION_FAILED−131A required PAC script could not be loadedCorporate network or policy

The distinction is about which leg of the journey broke. Leg one is your machine to the proxy; leg two is the proxy to the website. ERR_PROXY_CONNECTION_FAILED is always leg one. ERR_TUNNEL_CONNECTION_FAILED is always leg two, which is why re-checking a host and port that were correct all along wastes an afternoon.

The ten-second test

Before changing anything in Chrome, take the browser out of the picture. The same proxy through cURL, with verbose output, shows exactly what the proxy said.

bash
curl -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o /dev/null

# Windows PowerShell: use curl.exe, not the curl alias
curl.exe -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o NUL
Look at the line after '> CONNECT example.com:443'. Everything you need is in the proxy's reply.
cURL showsMeaningChrome equivalent
Failed to connect / Connection refusedNothing listening on that host and portERR_PROXY_CONNECTION_FAILED
Could not resolve proxyThe proxy hostname does not resolveERR_PROXY_CONNECTION_FAILED
Hangs, then times outA firewall is silently dropping packetsERR_PROXY_CONNECTION_FAILED
HTTP/1.1 407Credentials missing or wrongERR_TUNNEL_CONNECTION_FAILED
HTTP/1.1 403 or 405The proxy refuses that destination or portERR_TUNNEL_CONNECTION_FAILED
HTTP/1.1 502 or 503The proxy could not reach the websiteERR_TUNNEL_CONNECTION_FAILED
HTTP/1.1 200 Connection establishedProxy is fine — the problem is inside ChromeExtension, policy or profile

Every exit code cURL can return here is covered in cURL proxy errors.

Fixing ERR_PROXY_CONNECTION_FAILED

If you meant to use a proxy

  1. 1Check the port. A wrong port is the most common cause by a wide margin — HTTP and SOCKS5 usually listen on different ports, and pasting one into the other fails here.
  2. 2Check the protocol field. A SOCKS5 endpoint entered as an HTTP proxy, or the reverse, fails before any handshake.
  3. 3Check the host. A typo in a gateway hostname produces Could not resolve proxy in cURL and this error in Chrome.
  4. 4Allow outbound traffic on the proxy port. Office networks, school networks and some antivirus firewalls block unusual ports. Try a mobile hotspot to confirm.
  5. 5Confirm the plan is active. An expired or exhausted plan can close the listener rather than returning an error page.

If you did not set a proxy

Then something set one for you, and it is now pointing at an address that does not answer. Uninstalled VPN clients, ad blockers and adware are the usual suspects. Turn the system proxy off first:

  • Windows 10/11 — Settings → Network & internet → Proxy. Turn off Use a proxy server under Manual proxy setup, and turn off Use setup script unless your organisation requires it.
  • macOS — System Settings → Network → your connection → Details → Proxies. Untick everything you did not deliberately enable.
  • Chrome — open chrome://extensions and disable anything that mentions proxy, VPN or privacy, then reload.
  • Managed devices — open chrome://policy and look for ProxyServer, ProxyMode or ProxyPacUrl. A policy overrides every other setting and has to be changed where it was set.

If the proxy setting keeps turning itself back on after you disable it, something is rewriting it. On Windows, the value lives under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings as ProxyEnable and ProxyServer — run a malware scan and check which startup programs touch it.

chrome://net-internals/#proxy shows the proxy configuration Chrome is actually using right now, which is often not the one you think you set.

Fixing ERR_TUNNEL_CONNECTION_FAILED

The proxy is alive. Your job is to find out why it declined to open the tunnel, and the cURL status line above has already told you.

  • 407 — authentication. Chrome does not accept credentials in --proxy-server, so an automated browser never sends them. Either whitelist your IP or handle the challenge in code — see 407 Proxy Authentication Required.
  • Whitelist drift. If you authenticate by IP, check that your public address has not changed after a router restart or a VPN toggle. Our IP tool shows the address the proxy sees.
  • 403 or 405 — destination refused. Some proxies only tunnel to port 443, or block specific domains. Try a plain, neutral site; if that works, the proxy is filtering the one you wanted.
  • 502 or 503 — upstream failure. The proxy could not reach the site through its exit. Retry on a different exit or session; if every exit fails for one domain, the site is down or blocking that network.
  • Filtering software. Antivirus web shields, parental controls and school filters act as local proxies and refuse tunnels to sites they block. If only some sites fail, look there.

Proxies that answer on the first try

Residential from €1.20/GB and ISP from €1.80/IP, with username or IP-whitelist authentication and HTTP plus SOCKS5 on every plan.

See pricing

In automation: Selenium, Puppeteer and Playwright

Headless browsers produce the same codes, usually wrapped in an exception such as net::ERR_TUNNEL_CONNECTION_FAILED. In automation it is almost always the credentials: Chromium drops the user:pass@ part of a --proxy-server URL without warning, the proxy answers 407, and the browser reports a tunnel failure.

If nothing above helped

  1. 1Open a Guest window. If it works there, an extension or profile setting in your main profile is the cause.
  2. 2Reset network state on Windows with netsh winsock reset and ipconfig /flushdns from an elevated prompt, then reboot.
  3. 3Capture a log at chrome://net-export, reproduce the error once, and open it in the Netlog viewer. The failing CONNECT and the proxy's exact reply are in there.
  4. 4Send the proxy provider the timestamp, your public IP and the cURL output. That is enough for support to find the request on their side.

Sources

Frequently asked questions

What does ERR_PROXY_CONNECTION_FAILED mean?

Chrome could not open a connection to the proxy server configured on your system or in the browser. The proxy's hostname did not resolve, nothing was listening on the port, or a firewall blocked the connection. It happens before any website is contacted.

What is the difference between ERR_PROXY_CONNECTION_FAILED and ERR_TUNNEL_CONNECTION_FAILED?

ERR_PROXY_CONNECTION_FAILED means the proxy was never reached. ERR_TUNNEL_CONNECTION_FAILED means the proxy was reached but refused or failed to open the HTTPS tunnel to the website, typically because of a 407 authentication error, a blocked destination or an upstream failure.

How do I fix ERR_PROXY_CONNECTION_FAILED on Windows 11?

Open Settings, Network & internet, Proxy, and turn off Use a proxy server and Use setup script unless you deliberately configured them. Then disable proxy and VPN extensions in Chrome. If the setting returns after a reboot, scan for adware that rewrites it.

Why do I get ERR_TUNNEL_CONNECTION_FAILED with Selenium or Puppeteer?

Chromium ignores credentials embedded in the --proxy-server flag, so the proxy responds with 407 and the browser reports a tunnel failure. Use IP whitelisting, Puppeteer's page.authenticate, Playwright's proxy username and password, or a local forwarder that adds the credentials.

Can a VPN cause ERR_PROXY_CONNECTION_FAILED?

Yes. Some VPN clients set a system proxy while running and fail to remove it when they quit or are uninstalled, leaving Chrome pointed at a local port where nothing is listening.

How do I check which proxy Chrome is using?

Open chrome://net-internals/#proxy to see the effective configuration, and chrome://policy to see whether an administrator policy is forcing one.

SE
seamless Team
Proxy infrastructure

The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.

Ready to try seamless proxies?

Residential, ISP and datacenter proxies with no data expiry.

Browse Plans