Databay probe workbench

Free Proxy Checker

Test up to 100 public HTTP, HTTPS, SOCKS4 and SOCKS5 endpoints. Stream status, successful trace latency, protocol evidence, a probe-path header grade and exit country.

100
proxies per run
4
protocols + auto
Live
streaming results
Free
no signup, no key

The outbound test runs on Databay's probe network. A submitted proxy sees the checker service address, not a direct connection from your browser.

Probe pathprobe runs from checker network
  1. Your deviceoff-pathDoes not open the connection to the submitted proxy
  2. Databay probe networkRuns the test for you, off your machine
  3. Target proxyHTTP request · CONNECT path · SOCKS handshake
  4. Trace and header judgegradedReturns route evidence and a narrow header grade

HTTP · HTTPS · SOCKS4 · SOCKS5 · AUTO

Run a live probe

WebSocket result stream

Scheme prefixes like socks5:// are stripped automatically.

Up to 100 proxies per run

Results stream in live, row by row: status, latency, protocol, anonymity grade and exit country for every proxy, ready to sort, copy or export as .txt/.csv.

Why this checker

Built by the team that runs a proxy network

Databay runs a production proxy network and re-verifies its own free proxy list every 5 minutes. This tool exposes those same probes, with one important difference from most free checkers.

Your browser stays off the proxy path

The outbound test starts on Databay's checker network, not in your browser. A submitted proxy sees the checker service address; the website still receives your normal visit like any online service.

Real probes, not port scans

Each endpoint must complete a supported HTTP or SOCKS path and relay a valid trace request. An open port alone does not qualify as alive.

Live streaming results

Results appear row by row as each proxy is tested, up to 100 at a time, with copy, endpoint-only TXT export and a six-column CSV evidence record.

Check your proxies in three steps

  1. Paste your proxy list. One proxy per line, in ip:port format, for example 45.61.20.11:8080. You can check up to 100 at a time.

  2. Choose a protocol. Select HTTP, HTTPS, SOCKS4 or SOCKS5, or leave it on Auto-detect and the checker reports which supported path completes.

  3. Run the check and export the winners. Press Check proxies. Live results stream into a sortable table, then copy or download the proxies that pass as a .txt file.

What each column means

Alongside the submitted endpoint, the checker reports five observed or derived signals. Each one answers a narrow question.

Status
Alive means the checker completed a supported proxy path and received a valid trace response. Dead combines refusal, timeout, handshake failure and relay failure; the public row does not claim which stage failed.
Latency
One successful trace round trip from Databay’s checker region through the proxy, in milliseconds. It is not your device latency, throughput, or an average.
  • <300 mslower probe time: repeat from your workload region before choosing it
  • 300–800 msmoderate probe time: record variance across more than one run
  • >800 mshigher probe time: expect tighter clients to need a larger timeout

These bands are a reading aid, not a service grade. Compare repeated proxy runs with a direct baseline from the application and region that will do the real work.

Protocol
The path that completed. HTTPS means an HTTP proxy carried an HTTPS destination request; it does not say the checker-to-proxy hop used TLS. SOCKS labels require the corresponding handshake and a relayed TCP request.
Anonymity
A conventional probe-path header grade relative to Databay’s checker address. It does not test your browser, DNS, cookies, fingerprint, proxy-operator logging, or overall anonymity.
Exit country
The country code returned for the source address observed at the successful trace endpoint. Treat it as an IP-location estimate, not a physical-location guarantee.

Elite, anonymous and transparent explained

Elite, anonymous and transparent are long-used proxy-list labels. Here they describe what the Databay probe path exposed to a header judge, not whether a person is anonymous online.

LabelWhat this checker observed or inferredWhat the label does not prove
Elite (high-anonymous)A valid judge response exposed neither the checker address nor a proxy-revealing header, or the checker inferred the grade from the SOCKS tunnel path.Operator trust, DNS privacy, browser leak resistance, safety, or future behavior.
AnonymousThe checker address was hidden, but a Via, Forwarded, X-Forwarded-For, Proxy-Connection or similar intermediary signal was present.Which application identity or non-network signals a destination can correlate.
TransparentThe checker address was observed, or an unmeasurable HTTP user check received the cautious fallback grade.The exact failure mechanism or what a different client and destination would observe.

Use this grade to describe one network observation only. It is not a privacy certificate and should not be used to claim that an endpoint or person is anonymous.

Run a probe-path header check above

HTTP, HTTPS, SOCKS4 and SOCKS5 compared

The four result labels describe the path that passed this checker. They are not four encryption levels, and they do not all test the same capabilities.

Result labelEvidence required for a passing rowNot tested by that row
HTTPAn HTTP proxy relayed a valid plain-HTTP trace request.HTTPS destination support, proxy TLS, authentication, throughput, or other destinations.
HTTPSAn HTTP proxy relayed a valid HTTPS destination request, normally through an HTTP CONNECT tunnel.A TLS-protected checker-to-proxy hop. The submitted endpoint is still treated as an HTTP proxy.
SOCKS4A SOCKS4 handshake and a TCP trace request completed.SOCKS4a remote DNS, authentication, UDP, or non-HTTP workloads.
SOCKS5A no-auth SOCKS5 negotiation and a TCP trace request completed.Username/password or GSSAPI auth, UDP ASSOCIATE, DNS delegation, throughput, or non-HTTP workloads.

Protocol and measurement sources

  • RFC 9110: CONNECTDefines the HTTP method used to establish a blind tunnel to a destination.
  • RFC 1928: SOCKS5Defines method negotiation plus CONNECT, BIND and UDP ASSOCIATE requests.
  • RFC 7239: ForwardedDefines a proxy disclosure header and explains why forwarded values are not inherently trustworthy.
  • Cloudflare: /cdn-cgi/traceDocuments the trace endpoint family used for the successful route observation.

Browse the live free proxy list

Our proxy verification method

Every proxy you submit is routed through Databay's verification pipeline, the same system that re-checks our free proxy list every 5 minutes. The website relays submitted IP:port values to an isolated checker service, which performs the outbound probe from Databay’s network rather than your browser. Credentials are rejected; never paste secrets into the tool.

Auto-detect first probes SOCKS5 and SOCKS4, then verifies the candidate with a real trace request; an explicit protocol skips the unrelated handshakes. An applicable HTTP path then requests a header-echo judge through the same proxy. The classifier compares that response with Databay’s checker address and proxy-revealing headers:

Probe evidencePublic labelEvidence type
Checker address appears as the origin or in a forwarding headerTransparentMeasured by a valid judge response
Checker address is hidden, but a proxy-revealing header is presentAnonymousMeasured by a valid judge response
Valid judge response contains neither signalEliteMeasured by a valid judge response
Judge is unavailable for an HTTP user checkTransparentCautious fallback; not a measurement
SOCKS path completes an HTTPS trace tunnelEliteProtocol inference; no HTTP header judge needed
Judge is unavailable for another SOCKS pathEliteSOCKS tunnel fallback; not a judge measurement

The published latency is only the successful trace attempt, so a failed HTTPS attempt before an HTTP fallback is not added to the number. Country comes from that same trace response. The later header judge and connectivity probe do not inflate the displayed latency.

See the free proxy list we re-check every 5 minutes

What one proxy check can and cannot prove

A useful checker separates observations from conclusions. This is the evidence contract for one completed Databay run.

QuestionWhat one run can answerWhat needs another test
Can it relay?Yes, from the Databay checker region to the trace endpoint at this time.Your runtime, credentials, target destination and future availability.
Which protocol worked?The HTTP/HTTPS destination path or SOCKS version shown in the result.SOCKS5 UDP, delegated DNS, proxy TLS and unsupported authentication methods.
How fast was it?One successful trace round trip in milliseconds.Throughput, tail latency, concurrency, your region and application overhead.
What did the destination see?An exit-country estimate and a header grade for the checker path.Browser, DNS, cookie, fingerprint, account, trust or legal signals.
Is it safe to use?The checker does not answer this question.Operator ownership, logging, content integrity, authorization and security review.

The Databay Research Team reviewed and accepted this evidence contract on .

Four limits to keep with the result

Endpoint format
The public form accepts literal public IPv4 addresses with ports. It rejects hostnames, credentials, private ranges and local addresses before the run.
TCP web probe only
The relay request is HTTP or HTTPS over TCP. SOCKS5 UDP ASSOCIATE, application-specific protocols and DNS delegation are outside this result.
One remote vantage point
Status and latency describe Databay’s checker path at one moment. Network policy and routing can produce a different result from your region.
No trust certificate
A passing row does not prove that an unknown proxy is safe, private, correctly operated, authorized for your work, or unable to modify cleartext traffic.

Diagnose a dead result or client mismatch

Start with the narrowest explanation the result supports. Change one variable at a time and stop when the next step would cross a permission, authentication, quota or access-control boundary.

What you seeWhat it meansNext controlled checkStop condition
Input is rejected before the runNo valid public IPv4 ip:port rows survived local validation.Remove credentials and hostnames, or normalize a non-secret example in the format converter.Do not paste credentials or internal endpoints into a remote checker.
DeadThe checker did not complete connection, handshake and trace relay within the run budget.Retry once, then test the same endpoint from an authorized client and destination you control.Stop if ownership or permission is unclear; do not rotate identities to answer an access-control refusal.
Alive here, failing in your appThe checker path worked, but it did not test your authentication, DNS mode, TLS policy or destination.Pin the client version and compare one direct request with one proxied request to a controlled endpoint.Stop on a challenge, block, quota, authentication boundary or certificate error you cannot explain.
Latency changes between runsThe value is one remote round trip, so routing, load and the exit can change it.Record several runs with UTC times, then measure from the workload region using the same target and timeout.Do not promote one minimum result as typical performance.
Country differs from another lookupIP-location databases and routing observations can disagree.Record the observed exit IP and compare the same request in your application with a second documented source.Do not treat IP country as proof of physical presence or platform localization.

If the input itself is the problem, normalize a non-secret example with the browser-only proxy format converter. Conversion checks syntax; this page checks one remote network path.

Reproduce the route from your own client

Use one endpoint you own or are authorized to test. The online checker gives a remote observation; this two-request lab tells you whether your actual command-line client follows the same route.

Two-request route checkcurl · POSIX shell · one endpoint
# POSIX shell — enter a non-secret proxy URL such as http://IP:PORT
TARGET_URL='https://databay.com/what-is-my-ip/json'

# 1. Record the direct route.
curl --fail --silent --show-error \
  --connect-timeout 10 --max-time 30 \
  --write-out '\nconnect=%{time_connect}s total=%{time_total}s\n' \
  "$TARGET_URL"

# 2. Enter one authorized endpoint, then record the proxied route.
read -r PROXY_URL
curl --fail --silent --show-error \
  --connect-timeout 10 --max-time 30 \
  --write-out '\nconnect=%{time_connect}s total=%{time_total}s\n' \
  --proxy "$PROXY_URL" \
  "$TARGET_URL"

unset PROXY_URL TARGET_URL

The prompt keeps the endpoint out of this page and the example contains no credential. If your endpoint requires authentication, follow its provider's secure client instructions instead of submitting the credential here. curl documents the accepted proxy URL schemes in its official command reference.

FieldChecker runClient-side verification
UTC timeRecord when the row completedRecord each curl request time
Vantage pointDatabay checker networkYour runtime and region
Protocol inputAuto, HTTP, HTTPS, SOCKS4 or SOCKS5Exact proxy URL scheme used by curl
Observed routeCountry and header gradeDirect and proxied IP responses
TimingSuccessful trace round tripcurl total time from your runtime, measured separately
DecisionCandidate for a controlled client testAccept, investigate one mismatch, or reject

For the DNS difference between socks5:// and socks5h://, use the HTTP versus SOCKS5 wire-trace guide. This checker does not expose the client's DNS choice.

How Databay's checker compares

Proxy checkers use different architectures. Databay sends the outbound test from its checker network; a browser-side checker sends it from the user’s network. Check another tool’s documentation before assuming which design it uses.

CriterionDatabay proxy checkerBrowser-side checker design
Where the test runsFrom Databay’s checker networkFrom the user’s browser and network
Origin address seen by a tested proxyChecker service addressUser network address
Supported protocolsHTTP, HTTPS, SOCKS4, SOCKS5 and auto-detectLimited by the browser and implementation
ResultsStreamed into a sortable table with .txt and .csv exportImplementation-specific
AccessFree, no signup, no API key; abuse limits applyImplementation-specific

When free proxies are not enough

Free and public proxies can support low-stakes testing and learning. Ongoing work usually needs documented controls, support, capacity, and an availability target.

CriterionFree / public proxiesVerified proxies (Databay)
AvailabilityNo service commitment; endpoints can disappearPublished 99.9%+ uptime target
Header behaviorVaries by endpoint and needs a time-specific checkNetwork-specific controls and documentation
PerformanceOne endpoint and moment can vary widelyManaged capacity with published performance figures
Operator riskUnknown operators may inspect, log, or alter trafficNamed provider with privacy, security, and acceptable-use terms
Best forTesting, learning, one-off tasksProduction scraping and automation
When to use it

When to check your proxies

Any workflow that leans on proxies fails quietly when they die. Verify a list before these jobs, and again if success rates dip mid-run.

Web scraping

Remove endpoints that fail this remote probe, then reproduce one small authorized request from the crawler runtime before scaling.

Build a controlled preflight

Ad verification

Check that geo-targeted proxies exit in the right country before you audit how ads render for local users.

Verify exit countries

Market research

Remove endpoints that fail the remote probe, then validate latency and completeness from the permitted collection runtime.

Validate your list

SEO monitoring

Check the observed exit country, then confirm the same route in the authorized rank-tracking client before collecting localized results.

Test before you rank

Ecommerce and retail

Filter out endpoints that fail the remote probe before a permitted price or stock observation; verify the destination separately.

Filter for speed

Social media management

Use the result only as a time-specific network diagnostic for an authorized public-page check. It says nothing about account safety or platform permission.

Screen for leaks
Keep exploring

More free proxy tools

Free proxy list

Thousands of live public proxies, re-verified every 5 minutes and ready to paste straight into this checker.

Open the free proxy list

What is my IP

See the IP address, location and network that websites detect from your current connection.

Check your IP address

Residential proxies

Real-device IPs with 99.9%+ uptime for jobs where a free list will not cut it.

Explore residential proxies
Databay network

Free proxies for testing, verified proxies for production

Public proxies are useful for short-lived tests but can disappear without notice. For ongoing work, compare Databay paid pools by network origin, location coverage, targeting controls, protocol support, and price.

residential IPs
34M+
countries covered
200+
network uptime
99.9%+
average latency
~1.1s

Frequently Asked Questions

What is a proxy checker?
A proxy checker sends a controlled request through a submitted endpoint and reports what that run observed. Databay checks from its own probe network and returns status, successful trace latency, the path that completed (HTTP, HTTPS, SOCKS4 or SOCKS5), a probe-path header grade, and an exit-country estimate. Those results do not certify safety, anonymity, throughput, target compatibility, or future availability.
How do I check if a proxy is working?
Paste your proxies into the box, one per line, in ip:port format such as 45.61.20.11:8080. Choose a protocol or leave it on Auto-detect, then press Check proxies. Live results stream into a table you can sort, copy or export. There is no signup and no API key.
How many proxies can I check at once?
You can check up to 100 proxies per run. Results stream in one row at a time as each proxy is tested, so you see working proxies immediately instead of waiting for the whole batch to finish.
What do elite, anonymous and transparent mean?
They are conventional proxy-list labels for what Databay’s checker path observed or inferred. Elite means a valid judge response exposed neither the checker address nor a proxy-revealing header, or the checker inferred the grade from a SOCKS tunnel path. Anonymous means the checker address was hidden but a proxy signal was present. Transparent means the checker address was observed or an unmeasurable HTTP user check received the cautious fallback grade. None of the labels proves your overall anonymity, DNS privacy, browser leak resistance, operator trust, or future behavior.
Which proxy protocols and formats are supported?
The checker accepts literal public IPv4 endpoints in ip:port form and tests HTTP, HTTPS destination support, SOCKS4 and SOCKS5. Scheme prefixes such as socks5:// or http:// are accepted but stripped before the selected or auto-detected path is tested. An HTTPS result means an HTTP proxy carried a request to an HTTPS destination; it does not prove a TLS-protected client-to-proxy hop. Hostnames, private addresses and credential-bearing formats are rejected. Test authenticated proxies from a client or provider dashboard you trust.
How do I read the latency column?
Latency is one successful trace round trip from Databay’s checker region through the proxy, in milliseconds. It excludes a failed first trace attempt and the later header and connectivity probes. Use the displayed bands only as a reading aid, then compare repeated runs with a direct baseline from the application and region that will do the real work.
Why does my proxy show as dead?
Dead means the checker did not complete connection, protocol handling and a valid trace relay within the run budget. The public row deliberately does not claim whether the endpoint refused, timed out, failed a handshake, or failed to relay. Retry once, then reproduce one request from an authorized client and destination you control; a different region can produce a different result.
Can I check SOCKS5 proxies?
Yes. The checker negotiates SOCKS5 and requires a relayed TCP trace request, so an open port alone cannot pass. It does not test username/password or GSSAPI authentication, DNS delegation, UDP ASSOCIATE, throughput, or non-HTTP application traffic.
Does the checker test SOCKS5 UDP?
No. SOCKS5 defines both TCP relay requests and UDP ASSOCIATE, but this checker verifies the SOCKS5 negotiation followed by one relayed TCP trace request. It does not create a UDP association or send a test datagram.
Can I check proxies in bulk?
Yes. Paste up to 100 proxies per run and they are checked in parallel, with results streaming in as each one finishes. Export working results as .txt or .csv and run another check within the tool’s abuse-prevention limits; no signup or API key is required.
How are submitted proxies handled?
During a check, the website relays the submitted IP:port values to Databay’s isolated checker service. The UI does not save them to an account, credentials are rejected, and the tested proxies see the checker’s network address rather than your browser’s public IP. As with any online tool, do not submit secrets; operational infrastructure may produce security and diagnostic logs.
How often should I re-check proxies?
Public proxies can drop within minutes, so re-check any list right before you use it, and again if success rates fall during a job. Databay re-verifies its own free proxy list every 5 minutes for the same reason.
Is the proxy checker free?
Yes. The proxy checker is free to use, needs no account, and shows no ads. Abuse-prevention limits still apply.

Found the proxies that pass? Put them to work.

Check up to 100 free proxies above, and when the job has to succeed, route it through 34M+ residential IPs in 200+ locations with 99.9%+ uptime.

Free checker, no signup · paid plans are pay-as-you-go, no contracts