To create a proxy server, you run proxy software on a computer and let your devices send their requests to it. Squid and 3proxy are two free programs that do it. Then you lock it with a login, and you switch off the headers that pass your address on to every site.
That last step matters more than most guides admit. We ran both programs on our server on 11 October 2026: Squid 6.14 from Ubuntu's own packages and 3proxy 1.0.1 built from its source. With their default settings, both told the site at the other end who was using the proxy.
What do you need to create a proxy server?
Three things:
- A computer to run it on. Sites see the address of that computer. On your own PC, that is your own address, so the proxy hides nothing. On a rented server, it is the server's address.
- Proxy software. Squid is the large, classic one, with detailed access rules. 3proxy is small and serves HTTP and SOCKS5 from one program. Our page on proxy server software compares more of them.
- A way to keep strangers out: a login, or a rule that lets in only your own address.
How do you set up Squid?
On Ubuntu or Debian, Squid comes as a package:
sudo apt install squid
Its settings live in /etc/squid/squid.conf. Out of the box, Squid listens on port 3128 and serves only the machine it runs on. The shipped file says http_access allow localhost and then http_access deny all. We unpacked the same package, version 6.14, into a folder of our own and ran it with that file. A request from 127.0.0.1 went through. A request from 127.0.0.2, another address, got 403.
To use it from other devices, add a login. Make a password file:
printf 'proxyuser:%s\n' "$(openssl passwd -apr1 'your-password')" | sudo tee /etc/squid/passwords
Then put these lines in squid.conf, above http_access deny all:
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords
auth_param basic realm proxy
acl users proxy_auth REQUIRED
http_access allow users
Restart Squid with sudo systemctl restart squid. In our test, a request without the login got 407, and so did a wrong password. RFC 9110 explains the code: it "indicates that the client needs to authenticate itself in order to use a proxy for this request". The right login got 200, and an https page went through as a tunnel.
What does a default Squid tell the sites you visit?
Your address. We sent the same request to a small echo server of our own, which answers with every header it receives: once directly, and once through Squid with Ubuntu's settings.

Directly, curl sent three headers. Through Squid, the echo also got these:
X-Forwarded-For: 127.0.0.1, the address of the person using the proxy.Via: 1.1 squid-test (squid/6.14), which names the proxy and its version.Cache-Control: max-age=259200, which curl never sent.
Squid's reference describes the first one. With forwarded_for on, which is its default, "Squid will append your client's IP address in the HTTP requests it forwards." RFC 9110 says Via "indicates the presence of intermediate protocols and recipients between the user agent and the server". So a default Squid is a transparent proxy: the site sees both you and the proxy. Our page on transparent, anonymous and elite proxies explains the levels.
Two lines in squid.conf switch it off:
forwarded_for delete
via off
With them, X-Forwarded-For and Via were gone, but the Cache-Control header stayed. Its number matched Squid's shipped refresh_pattern rules: 259,200 seconds is their 4,320 minutes. One more line removed it as well: request_header_access Cache-Control deny all. After that, the request reached the echo as curl sent it, plus a Connection: keep-alive line.
All of this applies to http:// pages. On an https page, the proxy only opens a tunnel and, in the words of RFC 9110, restricts "its behavior to blind forwarding of data". It cannot add a header there. One more caution: Squid's reference marks both options as "not available in the v8 version of Squid". On a newer Squid, check its documentation.
How do you set up 3proxy?
Ubuntu's archive has no 3proxy package. The project's release page carries .deb and .rpm packages, Windows zip files and the source, each with a signature. We built release 1.0.1, from 10 October 2026, from its source with make -f Makefile.Linux, which took 30 seconds. Then we ran it as the unprivileged user nobody.
A config file with a login, an HTTP proxy and a SOCKS5 proxy takes five lines:
auth strong
users proxyuser:CL:your-password
allow proxyuser
proxy -p3128
socks -p1080
Its manual explains auth strong: "username/password authentication required. It will work with SOCKSv5, FTP, POP3 and HTTP proxy." CL means the password stands in the file as plain text, so keep the file private. Start it with 3proxy /path/to/3proxy.cfg. Our test ran on 127.0.0.1, on free ports:

Without the login, 407. With it, the page came through, and https and SOCKS5 worked too. SOCKS5 without the login got no answer at all.
3proxy passed the user on as well, in another header: Forwarded: for=127.0.0.1:52126;by=SERVER-NAME:51819. The for part is the user's address and port. The by part named our server, which we masked in the capture. RFC 7239, the standard for this header, says a proxy's default here "SHOULD contain an obfuscated identifier". 3proxy sent the real values. Its manual offers the fix, the -a flag: "Anonymous. Hide information about client." With proxy -a -p3128, the header was gone.
How do you check what your proxy tells websites?
Ask a page that shows every header. httpbin.org does that when you add show_env=1, over plain http:
curl -x http://proxyuser:your-password@your-server:3128 "http://httpbin.org/headers?show_env=1"
We ran it through a default Squid. httpbin showed X-Forwarded-For: 127.0.0.1 followed by our server's address, and Via: 1.1 squid-test (squid/6.14). The first address in X-Forwarded-For is the person using the proxy. httpbin's own front end adds the last one, the address that connected to it. If your home address shows up there, or a Via header appears, the proxy is passing you on. Our page on using proxies with curl covers the other checks.
Should you build a proxy or buy one?
Build one when one address is enough: your own server's. It suits reaching a network you control, filtering or caching for a team, or a fixed address for a firewall rule.
It cannot give you other addresses. Every request leaves from the machine it runs on, and httpbin saw our server's address as the connecting one, with or without Squid. A rented server's address belongs to a hosting company, and our page on how to check if an IP is residential shows how easily sites read that. For many addresses, other countries, or home connections, residential proxies are the tool.
What this page could not check
- One server, Squid 6.14 from Ubuntu's packages and 3proxy 1.0.1 built from source, each on 127.0.0.1 and never open to the internet.
- We did not test Squid 7 or 8, firewall rules, TLS to the proxy, or Squid's cache.
- The leaking headers were read on
http://pages; https pages carry none of them. - We will run the tests again by 11 January 2027.
Sources
- Squid, configuration reference for forwarded_for and via, read 11 October 2026: squid-cache.org.
- Ubuntu, squid 6.14-0ubuntu0.24.04.4 and the squid.conf it ships, read 11 October 2026: packages.ubuntu.com.
- 3proxy, manual pages of release 1.0.1, 10 October 2026: github.com.
- RFC 7239, Forwarded HTTP Extension, IETF, June 2014: rfc-editor.org.
- RFC 9110, HTTP Semantics, Via, 407 and CONNECT, IETF, June 2022: rfc-editor.org.
- Our own tests on our server, 11 October 2026: squid_test.sh at 16:57 UTC, 3proxy_test.sh at 17:02 UTC, showenv_test.sh at 17:13 UTC.



