How to check proxy in Edge on Windows and macOS

EdgeMicrosoft Edge has no proxy field of its own. It reads the proxy configured in the operating system, so the short answer to how to check proxy in Edge is this: open edge://settings/system, click "Open your computer's proxy settings" and read what Windows or macOS shows.

That page doesn't always match what Edge uses. A group policy, an extension or a launch flag can override the system proxy without changing anything on the Windows screen. To check proxy settings in Edge fully, look in four more places: edge://policy, edge://extensions, edge://version and a NetLog capture from edge://net-export.

Steps 1 and 2 below cover how to check proxy settings in Edge at the system level. They take about two minutes and need no admin rights.

 

Steps 3 to 7 deal with policies, flags and logs. That part is for IT support staff, QA engineers testing region-specific pages and developers who run Fiddler or Charles as a local debugging proxy.

Whichever group you're in, the check answers three questions: which proxy Edge uses right now, whether that proxy accepts connections, and whether websites see its IP address instead of yours.

Where to check proxy settings in Edge

Edge runs on Chromium, so it takes its proxy from the highest-priority source that has a value. In order of precedence: an enterprise policy, an extension using the chrome.proxy API, command-line switches and, last, the operating system. Each layer hides everything below it.

proxy in Edge

On Windows, the system layer is the per-user WinINet configuration stored in HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings. The Settings app and the older Internet Options dialog (inetcpl.cpl) edit the same values, so they always agree with each other.

Proxy sources Edge reads, highest priority first

Source

Where to check

Applies to

Advantage

Drawback

Enterprise policy (ProxySettings)

edge://policy

Edge on that device or profile

Set centrally, users can't change it

Blocks local testing; Edge ignores proxy flags while it's set

Browser extension

edge://extensions, plus a note on the settings page

One Edge profile

Browser-only proxy, several entries, one-click switching

Overrides the system proxy without warning; can sync to other PCs with the profile

Command-line flag

Command line row in edge://version

One Edge process

Per-shortcut setup, handy for tests

Ignored if Edge is already running

Manual system proxy

Windows: Settings > Network & internet > Proxy. macOS: Network > Details > Proxies

Every app that follows system settings

No extra software

No login field; reroutes other apps too

PAC script or WPAD

Same page: Use setup script, Automatically detect settings

Rules per URL or host

Different proxy per domain

You have to read the script to know which proxy a site gets

On a single computer, the manual system proxy is the easiest to check and explain. To test several proxies side by side, use an extension or a separate Edge profile launched with --proxy-server, which leaves the rest of Windows on a direct connection.

One Windows layer never affects Edge: WinHTTP. netsh winhttp show proxy reports the proxy used by services such as Windows Update, not by the browser. Seeing "Direct access (no proxy server)" there while Edge goes through a proxy is normal, and netsh winhttp reset proxy won't fix an Edge problem.

Edge handles HTTP, HTTPS, SOCKS4 and SOCKS5 proxies. When a provider lists "HTTPS" support, it usually means an HTTP proxy that tunnels encrypted sites through the CONNECT method. Edge treats it as a normal HTTP proxy with a host and a port.

Authentication is the catch. Edge asks for a login and password only when an HTTP or HTTPS proxy replies with status 407. Chromium has no support for SOCKS5 username and password authentication, so a password-protected SOCKS5 proxy fails in Edge even when the address is correct.

For this setup, try HTTP(S) proxies with password authentication. Individual IPv4 plans on proxys.io cost from $1.47 per month, cover more than 20 countries and include HTTP, HTTPS and SOCKS, so SOCKS stays available for apps like Proxifier.

How to check proxy settings in Microsoft Edge step by step

Below is how to check proxy settings in Edge browser builds on Windows 11 and macOS. On Windows 10 the proxy page uses toggles instead of Set up and Edit buttons; the fields themselves are the same.

  1. Open edge://settings/system and click "Open your computer's proxy settings". Windows opens Settings > Network & internet > Proxy. If Edge says an extension or your organization manages the setting, skip to steps 3 and 4.
  2. Click Edit next to "Use a proxy server" to see the proxy address, port and exception list. Above it you'll see whether "Automatically detect settings" is on and whether "Use setup script" points to a PAC file.
  3. Go to edge://extensions and turn off proxy switchers or browser VPN add-ons one at a time, reloading your test page after each. If the IP or the error changes, that extension was setting Edge's proxy.
  4. Open edge://policy and type "proxy" in the search box. An empty list means no policy. Rows such as ProxySettings or ProxyMode mean your organization sets the proxy, and the Windows page no longer applies to Edge.
  5. Open edge://version and find the Command line row. A --proxy-server, --proxy-pac-url or --no-proxy-server flag there came from the shortcut; you'll see it in the shortcut's Properties, in the Target field.
  6. Go to edge://net-export, click Start Logging to Disk, open the problem site and click Stop Logging. Load the file into NetLog Viewer at netlog-viewer.appspot.com; its Proxy tab shows the proxy Edge actually applied.
  7. Open https://api.ipify.org or ipinfo.io with the proxy on. The page shows the proxy's IP and country instead of your ISP's. A password-protected proxy first brings up a sign-in window with the proxy's address.

On a Mac, how to check proxy settings on Edge comes down to the same link, which opens System Settings > Network > Details > Proxies. Running scutil --proxy in Terminal prints the same values, including HTTPProxy, HTTPPort and ProxyAutoConfigURLString.

If "Use setup script" has an address, open it in Edge and read the FindProxyForURL function: it returns the proxy for each host, and DIRECT means no proxy. "Automatically detect settings" is on by default in Windows and changes nothing on networks without a WPAD server.

Extension settings apply only to the current Edge profile, which is why a second profile on the same PC can behave differently.

An extension is also the simplest way to give Edge its own proxy without touching Windows. Try Proxy Control from proxys.io: it stores HTTP(S) proxies with logins and switches between them in one click. Edge installs it from the Chrome Web Store after you allow extensions from other stores.

Proxy policies live under SOFTWARE\Policies\Microsoft\Edge in HKLM or HKCU, and only an administrator can change them. edge://management shows whether the browser is managed at all.

Flags apply only when a new Edge process starts. With any window open, or with Startup boost keeping msedge.exe in the background on Windows, a shortcut with --proxy-server opens a window in the running process and the flag is dropped.

So before you check proxy settings, Edge needs a clean start: turn off Startup boost in edge://settings/system, or launch the test copy with its own --user-data-dir folder.

edge://net-internals/#proxy no longer displays settings in current Chromium builds. It keeps two buttons: Re-apply settings, which reloads the configuration without a restart, and Clear bad proxies. When a fallback exists, Chromium marks a failed proxy as bad for 5 minutes, so clear it after a fix.

A net-export capture strips cookies and credentials by default, but URLs stay in the file, so review it before sending it to anyone.

To separate proxy faults from Edge faults, test the same proxy outside the browser with the curl.exe that ships with Windows 10 and 11: curl.exe -x http://user:pass@203.0.113.10:8080 https://api.ipify.org. URL-encode special characters in the password, such as @ as %40.

curl ignores the Windows proxy settings, so the result depends only on the proxy. If curl returns the proxy's IP and Edge doesn't, the fault is in one of Edge's configuration layers, not with the provider.

The country an IP-check page reports matters most in QA work on region-specific pages. For those tests, try Premium IPv4 proxies from proxys.io: they cover more than 195 countries, start at $3.60 per month and work as private proxies, so nobody else shares the address.

How to check proxy and firewall in Microsoft Edge

For timeouts and refused connections, Edge's error page suggests "Checking the proxy and the firewall". That hint shows up for many failures that have nothing to do with a proxy, while real proxy failures usually name the proxy server directly. Read the error code under the message before changing anything.

How to check proxy and firewall: Microsoft Edge error codes and first checks

Error code

What it means

Check first

ERR_PROXY_CONNECTION_FAILED

Edge couldn't open a TCP connection to the proxy host and port

Typos in the address or port, provider status, outbound firewall rules, a leftover 127.0.0.1:8888 entry

ERR_TUNNEL_CONNECTION_FAILED

The proxy answered but refused or failed the CONNECT tunnel to the site

An IP allowlist on the proxy that doesn't include your current IP, or a site the proxy owner blocks

ERR_SOCKS_CONNECTION_FAILED

The SOCKS handshake failed

Most often a SOCKS5 proxy that requires a password, or the wrong SOCKS version

ERR_MANDATORY_PROXY_CONFIGURATION_FAILED

The PAC script couldn't be loaded or run, and policy forbids a direct fallback

Whether the PAC URL opens; ProxyPacMandatory in edge://policy

ERR_NO_SUPPORTED_PROXIES

None of the configured proxies uses a type Edge supports

The scheme in the flag, the policy or the PAC return value

ERR_CONNECTION_TIMED_OUT

No reply arrived before the timeout

A firewall that drops packets silently, or an overloaded proxy

Before changing firewall rules, test whether the proxy port is reachable at all. In PowerShell, run Test-NetConnection 203.0.113.10 -Port 8080. A result of TcpTestSucceeded : True means nothing on the path blocks the connection, so look at credentials and Edge settings instead.

False points to a block between you and the proxy: Windows Defender Firewall, a security suite, the router or a corporate firewall that lets traffic out only through the company proxy. On office networks the last case is common, and the fix belongs to IT rather than to your laptop.

Windows Defender Firewall allows outbound traffic by default, so a block there comes from a custom rule. The "Allow an app through firewall" screen covers inbound connections only. For outbound rules, run wf.msc, open Outbound Rules and sort by Program, looking for msedge.exe or the proxy's port.

Security suites with web protection, such as ESET, Kaspersky or Bitdefender, filter HTTPS traffic locally and can interfere with proxy connections. Pause web protection for one test. If Edge connects, add the proxy host to the suite's exclusions instead of leaving protection off.

The fastest isolation test takes ten seconds. Turn off "Use a proxy server" and reload. If the page opens directly, the network works and the fault is in the proxy path. If it still fails, the proxy was never the problem.

Common mistakes and security blind spots

  • Leaving a debugging proxy behind. Fiddler Classic and Charles set the system proxy to 127.0.0.1:8888 while they run. After a crash the entry can stay, and every page in Edge fails with ERR_PROXY_CONNECTION_FAILED until you switch it off.
  • Checking the wrong Windows account. The manual proxy is stored per user, so an administrator account, a Remote Desktop session or an automation tool running Edge under a service account can each see a different proxy.
  • Assuming "Don't use the proxy server for local (intranet) addresses" covers private IPs. It adds the <local> rule, which matches only host names without a dot, such as intranet or nas. Requests to 192.168.1.20 still go through the proxy unless you add 192.168.* to the exceptions.
  • Typing credentials into the address field. Windows has no login field for a manual proxy, and entries like user:pass@203.0.113.10 break parsing. Enter only the IP and port; Edge asks for the password itself.
  • Testing on a site that bypasses the proxy. If the IP-check site matches an exception or a PAC rule that returns DIRECT, you'll see your real IP even though every other site goes through the proxy.

A correct exit IP doesn't prove that nothing escapes the proxy. WebRTC in Edge can contact STUN servers over UDP outside an HTTP proxy, which may expose your public address to a page's JavaScript. Run a WebRTC leak test right after the IP check.

Managed environments can close this gap with the Edge policy WebRtcLocalhostIpHandling set to disable_non_proxied_udp. WebRTC then goes through the proxy or not at all, which can degrade or break calls on video services that depend on UDP.

DNS behavior depends on the proxy type. With HTTP, HTTPS and SOCKS5 proxies, Edge sends the host name to the proxy, which resolves it. With SOCKS4, Edge resolves names locally, so your DNS provider still sees every domain you open.

The link between Edge and a regular HTTP proxy is not encrypted. HTTPS sites stay encrypted inside the CONNECT tunnel, so the proxy sees domain names and traffic volume but not page content. Plain http:// pages and the Basic authentication header travel in readable form, which matters on shared Wi-Fi.

Treat a proxy you didn't configure as a security finding. A PAC address on an unfamiliar domain, or a 127.0.0.1 port with no debugging tool installed, is a known adware technique for injecting ads and reading traffic. Remove the entry, then run a Microsoft Defender Offline scan.

FAQ

Does Edge sync proxy settings between devices?

No. Proxy settings live in the operating system, so signing in to Edge on a new PC doesn't bring them along. Extensions do sync, though, so a proxy extension can reappear on another computer after sign-in and, depending on how it stores its settings, start controlling Edge there.

Which check should I run first?

If pages fail with an ERR_ code, run Test-NetConnection against the proxy port first, because a closed port makes every setting irrelevant. If pages load with the wrong IP, go down the layers. In Edge, check proxy settings in order of precedence: edge://policy, edge://extensions, edge://version, then system settings.

Why does Edge still show my real IP after I set a proxy?

The usual causes are a PAC rule or exception that sends the IP-check site direct, a policy set to direct, a disabled extension, or a proxy configured under a different Windows user. A VPN client that manages the system proxy can also rewrite the entry each time it reconnects.