An open proxy list is a public list of proxy servers that anyone can use, with no login, password or allowlist. Most free proxy lists are open proxy lists. They are also mostly out of date. Of 318,682 entries our scraper found on public lists from 13 May to 28 September 2026, on addresses that held fewer than 20 of them, 270,533 never worked once. Counting every entry, 479,657 of 870,226 never worked.
This page covers what an open proxy is, why proxies end up open, what our own pool shows, and how to use one without handing over an account.
What an open proxy is
Wikipedia calls it "a type of proxy server that is accessible by any Internet user". A private proxy asks for a login, or accepts only a list of known addresses. An open proxy forwards traffic for whoever finds it. Publish a batch of those addresses and ports, and you have an open proxy list.
Why proxies end up open
There is little research on it. A 2018 study of more than 107,000 listed open proxies says the question has not undergone rigorous study. It says that "In some instances, the proxies are due to misconfiguration or even compromise". It adds: "Still, many proxies are operated by choice". Wikipedia notes that a computer can run as an open proxy "without the computer's owner knowing it".
Common proxy software does not ship open. The documentation of Squid says its "default configuration only allows localhost requests". Tinyproxy allows everyone only when its configuration has no access lines left at all. With these programs, an open proxy comes from an edit, a leftover setting or a choice. Our guide to proxy server software covers the defaults of each program.
What our own data shows
Our free proxy list is built from public lists, so we see what they hold. The numbers below come from one read-only query on our server at 14:40 UTC on 28 September 2026. Each figure leaves out addresses that held 20 or more of the entries it counts, and where that moves a figure a lot, both are given.
- Elite: hid your address and the proxy41%
- Anonymous: hid your address, showed a proxy33%
- Transparent: passed your own address on26%

- Most entries never work. 270,533 of 318,682 entries found since 13 May never worked once, 84.9 percent. Counting every entry, it was 479,657 of 870,226, 55.1 percent. A 2018 study found that "92% of advertised proxies listed on open proxy aggregator sites are nonfunctional".
- The rest do not last. Of 5,976 entries first seen from 13 to 19 September, 245 were working on 28 September, 4.1 percent. Counting every entry, it was 437 of 18,893. Those that worked and then stopped lasted a median 10 days, counting only addresses with fewer than 20 of them, without Amazon's networks or one June evening when our checker failed (measured 2026-09-28).
- HTTPS. 1,815 of 3,461 working web proxies opened an HTTPS tunnel, about half. Counting every entry, 3,079 of 10,072 did. The rest carried only plain HTTP, which nothing encrypts.
- Your address. 912 of the 3,461 were transparent and passed your own address on to the site, about one in four. Counting every entry, it was 964 of 10,072. On the default port of Squid, 3128, it was 99 of 273.
- Networks. 860 of 4,156 working entries were labelled datacenter, 20.7 percent. Counting every entry, it was 8,595 of 11,952, 71.9 percent.
The risks of an open proxy
A proxy sits in the middle of your traffic, and on an open list you do not know who runs it.
- It can change what you load. The 2018 study found misbehavior "including the insertion of spurious ads and cryptocurrency-mining Javascript, TLS MitM, and the injection of RATs", which are remote-access trojans.
- It can read plain HTTP. Over HTTPS, a proxy opens a tunnel with the CONNECT method, which RFC 9110 limits to "blind forwarding of data". Over plain HTTP, nothing is encrypted between you and the site.
- It can give your address away. A transparent proxy passes your IP address to the site. RFC 7239 names X-Forwarded-For among "the non-standard header fields" used to pass it on. Squid adds it by default: "If set to "on", Squid will append your client's IP address in the HTTP requests it forwards".
- Sites already know the address. Cloudflare lists "known open proxies" among the simplest IP reputation signals. Wikipedia notes that methods "have been developed to detect them and to refuse service to them".
How to use an open proxy more safely
- Public pages only. Never a login, a payment or a form with your name in it.
- HTTPS only. About half of the working free web proxies in our pool could not open an HTTPS tunnel, so skip those. Never click past a certificate warning.
- Elite only. A transparent proxy passes your own address on, and the grade can change between checks.
- Check it right before you use it. A proxy that worked an hour ago may be gone.
Our guides on whether free proxies are safe and when free proxies are fine cover the rest.
A checked list beats a raw one
A raw list says an address was open at some moment in the past. Our free proxy list shows only entries that worked within the last 48 hours. Before you trust any entry, from our list or any other, paste it into our free proxy checker, with no signup. It makes a real connection through the proxy and reports the exit address, country, latency and anonymity grade. From the command line, the same check is one request.
# Tests one proxy from our server: alive or dead, protocols, anonymity, latency, country
curl "https://hproxy.com/api/proxy-check?proxy=203.0.113.7:1080"
The full method is in how to check if a proxy is working.
When free is not enough
For web tasks that have to keep running, such as checking your own site from another country, a residential proxy is the better tool. Its address belongs to a home connection, and it stays up while you work. Ours start at $0.44/GB, pay as you go, and purchased traffic has no scheduled expiry date.
The plain answer
An open proxy list is a list of proxies anyone can use, run by people you do not know. Most entries on such lists never work, the rest stop within days, and about half of the working web proxies carry only plain HTTP. About one in four passed your own address on. Use one only for public pages, over HTTPS, and never sign in through one.
How we measured
All counts come from one read-only query of our free proxy pool, run from our server in the United States on 28 September 2026 at 14:40 UTC. Each figure leaves out addresses that held 20 or more of the entries it counts, and where that moves a figure a lot, the page gives both. Anonymity is graded from a plain HTTP request through each proxy to our own echo. We store no proxy addresses from these counts, and every time is in UTC.
Sources
- Wikipedia, Open proxy, last edited 15 June 2026.
- Akshaya Mani, Tavish Vaidya, David Dworken and Micah Sherr, An Extensive Evaluation of the Internet's Open Proxies, arXiv 1806.10258, 27 June 2018.
- Squid documentation: http_access and forwarded_for; the tinyproxy sample configuration.
- IETF, RFC 9110: HTTP Semantics, June 2022, section 9.3.6 on CONNECT.
- IETF, RFC 7239: Forwarded HTTP Extension, June 2014.
- Cloudflare blog, on detecting bot attacks from residential proxies with machine learning, 24 June 2024, updated 15 July 2026.
- HProxy documentation: the proxy checker API, read 28 September 2026.


