Skip to content
How proxies work

What is CONNECT Method?

The HTTP request a client sends to a proxy to open a raw tunnel to a destination host, used for every HTTPS site accessed through an HTTP proxy.

When a client wants an HTTPS page through an HTTP proxy, it first sends CONNECT example.com:443. If the proxy agrees it answers 200 Connection established, and from then on it simply relays bytes in both directions while the client and the website negotiate TLS directly.

That is why a proxy cannot read HTTPS traffic it tunnels, and why the proxy only gets one chance to report a problem: its reply to CONNECT. A 407 there means missing credentials, a 403 or 405 a refused destination, and a 502 an exit that could not reach the site.

Most proxy debugging comes down to reading that single reply. curl -v prints it, and browsers translate a refused CONNECT into ERR_TUNNEL_CONNECTION_FAILED.