ERR_PROXY_CONNECTION_FAILED and ERR_TUNNEL_CONNECTION_FAILED: What Each Means and How to Fix It
ERR_PROXY_CONNECTION_FAILED means Chrome could not reach the proxy at all: the address did not resolve, the port was closed, or something on your machine blocked the connection. ERR_TUNNEL_CONNECTION_FAILED means Chrome did reach the proxy, but the proxy refused to open the HTTPS tunnel — usually because of missing credentials, a blocked destination, or an upstream it could not reach. They look alike on screen and need opposite fixes, so the first step is always to identify which one you have.
- troubleshooting
- chrome
- proxy errors
- windows

Table of contents
Chrome's error page for the first one reads *There is something wrong with the proxy server, or the address is incorrect*. The second often lands on a generic *This site can't be reached* screen with the code at the bottom. Either way, the code is the useful part.
Which error you have, and what it tells you
| Error | Code | What failed | Where to look |
|---|---|---|---|
ERR_PROXY_CONNECTION_FAILED | −130 | No connection to the proxy at all | Host, port, firewall, system proxy settings |
ERR_TUNNEL_CONNECTION_FAILED | −111 | Proxy reached, CONNECT tunnel refused | Credentials, whitelist, blocked port or target |
ERR_PROXY_CERTIFICATE_INVALID | −136 | The HTTPS proxy's own certificate is invalid | Proxy scheme — you probably meant http:// |
ERR_NO_SUPPORTED_PROXIES | −336 | No proxy in the list uses a scheme Chrome supports | Typo in the scheme, e.g. socks:// with auth |
ERR_MANDATORY_PROXY_CONFIGURATION_FAILED | −131 | A required PAC script could not be loaded | Corporate network or policy |
The distinction is about which leg of the journey broke. Leg one is your machine to the proxy; leg two is the proxy to the website. ERR_PROXY_CONNECTION_FAILED is always leg one. ERR_TUNNEL_CONNECTION_FAILED is always leg two, which is why re-checking a host and port that were correct all along wastes an afternoon.
The ten-second test
Before changing anything in Chrome, take the browser out of the picture. The same proxy through cURL, with verbose output, shows exactly what the proxy said.
curl -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o /dev/null
# Windows PowerShell: use curl.exe, not the curl alias
curl.exe -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o NUL| cURL shows | Meaning | Chrome equivalent |
|---|---|---|
Failed to connect / Connection refused | Nothing listening on that host and port | ERR_PROXY_CONNECTION_FAILED |
Could not resolve proxy | The proxy hostname does not resolve | ERR_PROXY_CONNECTION_FAILED |
| Hangs, then times out | A firewall is silently dropping packets | ERR_PROXY_CONNECTION_FAILED |
HTTP/1.1 407 | Credentials missing or wrong | ERR_TUNNEL_CONNECTION_FAILED |
HTTP/1.1 403 or 405 | The proxy refuses that destination or port | ERR_TUNNEL_CONNECTION_FAILED |
HTTP/1.1 502 or 503 | The proxy could not reach the website | ERR_TUNNEL_CONNECTION_FAILED |
HTTP/1.1 200 Connection established | Proxy is fine — the problem is inside Chrome | Extension, policy or profile |
Every exit code cURL can return here is covered in cURL proxy errors.
Fixing ERR_PROXY_CONNECTION_FAILED
If you meant to use a proxy
- 1Check the port. A wrong port is the most common cause by a wide margin — HTTP and SOCKS5 usually listen on different ports, and pasting one into the other fails here.
- 2Check the protocol field. A SOCKS5 endpoint entered as an HTTP proxy, or the reverse, fails before any handshake.
- 3Check the host. A typo in a gateway hostname produces
Could not resolve proxyin cURL and this error in Chrome. - 4Allow outbound traffic on the proxy port. Office networks, school networks and some antivirus firewalls block unusual ports. Try a mobile hotspot to confirm.
- 5Confirm the plan is active. An expired or exhausted plan can close the listener rather than returning an error page.
If you did not set a proxy
Then something set one for you, and it is now pointing at an address that does not answer. Uninstalled VPN clients, ad blockers and adware are the usual suspects. Turn the system proxy off first:
- Windows 10/11 — Settings → Network & internet → Proxy. Turn off Use a proxy server under Manual proxy setup, and turn off Use setup script unless your organisation requires it.
- macOS — System Settings → Network → your connection → Details → Proxies. Untick everything you did not deliberately enable.
- Chrome — open
chrome://extensionsand disable anything that mentions proxy, VPN or privacy, then reload. - Managed devices — open
chrome://policyand look forProxyServer,ProxyModeorProxyPacUrl. A policy overrides every other setting and has to be changed where it was set.
If the proxy setting keeps turning itself back on after you disable it, something is rewriting it. On Windows, the value lives under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings as ProxyEnable and ProxyServer — run a malware scan and check which startup programs touch it.
chrome://net-internals/#proxy shows the proxy configuration Chrome is actually using right now, which is often not the one you think you set.
Fixing ERR_TUNNEL_CONNECTION_FAILED
The proxy is alive. Your job is to find out why it declined to open the tunnel, and the cURL status line above has already told you.
- 407 — authentication. Chrome does not accept credentials in
--proxy-server, so an automated browser never sends them. Either whitelist your IP or handle the challenge in code — see 407 Proxy Authentication Required. - Whitelist drift. If you authenticate by IP, check that your public address has not changed after a router restart or a VPN toggle. Our IP tool shows the address the proxy sees.
- 403 or 405 — destination refused. Some proxies only tunnel to port 443, or block specific domains. Try a plain, neutral site; if that works, the proxy is filtering the one you wanted.
- 502 or 503 — upstream failure. The proxy could not reach the site through its exit. Retry on a different exit or session; if every exit fails for one domain, the site is down or blocking that network.
- Filtering software. Antivirus web shields, parental controls and school filters act as local proxies and refuse tunnels to sites they block. If only some sites fail, look there.
Proxies that answer on the first try
Residential from €1.20/GB and ISP from €1.80/IP, with username or IP-whitelist authentication and HTTP plus SOCKS5 on every plan.
In automation: Selenium, Puppeteer and Playwright
Headless browsers produce the same codes, usually wrapped in an exception such as net::ERR_TUNNEL_CONNECTION_FAILED. In automation it is almost always the credentials: Chromium drops the user:pass@ part of a --proxy-server URL without warning, the proxy answers 407, and the browser reports a tunnel failure.
- Playwright accepts
usernameandpasswordin the proxy option and handles the challenge for you — see Playwright proxies. - Puppeteer needs
page.authenticate()before the first navigation — see Puppeteer proxy authentication. - Selenium has no built-in answer; whitelisting or a local forwarder is the reliable route — see Selenium proxy authentication.
If nothing above helped
- 1Open a Guest window. If it works there, an extension or profile setting in your main profile is the cause.
- 2Reset network state on Windows with
netsh winsock resetandipconfig /flushdnsfrom an elevated prompt, then reboot. - 3Capture a log at
chrome://net-export, reproduce the error once, and open it in the Netlog viewer. The failingCONNECTand the proxy's exact reply are in there. - 4Send the proxy provider the timestamp, your public IP and the cURL output. That is enough for support to find the request on their side.
Sources
Frequently asked questions
What does ERR_PROXY_CONNECTION_FAILED mean?
Chrome could not open a connection to the proxy server configured on your system or in the browser. The proxy's hostname did not resolve, nothing was listening on the port, or a firewall blocked the connection. It happens before any website is contacted.
What is the difference between ERR_PROXY_CONNECTION_FAILED and ERR_TUNNEL_CONNECTION_FAILED?
ERR_PROXY_CONNECTION_FAILED means the proxy was never reached. ERR_TUNNEL_CONNECTION_FAILED means the proxy was reached but refused or failed to open the HTTPS tunnel to the website, typically because of a 407 authentication error, a blocked destination or an upstream failure.
How do I fix ERR_PROXY_CONNECTION_FAILED on Windows 11?
Open Settings, Network & internet, Proxy, and turn off Use a proxy server and Use setup script unless you deliberately configured them. Then disable proxy and VPN extensions in Chrome. If the setting returns after a reboot, scan for adware that rewrites it.
Why do I get ERR_TUNNEL_CONNECTION_FAILED with Selenium or Puppeteer?
Chromium ignores credentials embedded in the --proxy-server flag, so the proxy responds with 407 and the browser reports a tunnel failure. Use IP whitelisting, Puppeteer's page.authenticate, Playwright's proxy username and password, or a local forwarder that adds the credentials.
Can a VPN cause ERR_PROXY_CONNECTION_FAILED?
Yes. Some VPN clients set a system proxy while running and fail to remove it when they quit or are uninstalled, leaving Chrome pointed at a local port where nothing is listening.
How do I check which proxy Chrome is using?
Open chrome://net-internals/#proxy to see the effective configuration, and chrome://policy to see whether an administrator policy is forcing one.
The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.
Ready to try seamless proxies?
Residential, ISP and datacenter proxies with no data expiry.
Browse PlansKeep reading
407 Proxy Authentication Required: Every Cause and Its Fix
The one proxy error that is entirely on your side of the connection — and the handful of clients that cause it even when your credentials are perfect.
TroubleshootingcURL Proxy Errors Explained: Exit Codes 5, 7, 28, 35, 56 and 97
cURL is the fastest way to prove whether a proxy works — once you can read what it is telling you. Every exit code maps to one leg of the connection.
TroubleshootingProxy Error Codes Explained: 407, 429, 502 and the Rest
Which errors come from the proxy and which from the target, why that distinction saves hours, and the specific fix for each code.
