Free tool
PAC file tester see where a browser sends any address
Paste a proxy auto-config file and the addresses you care about. Each one runs through FindProxyForURL the way Chrome or Firefox would run it, with every entry of the answer explained and every isInNet, shExpMatch and dnsResolve call shown. It all runs in your browser: the file is never uploaded.
Run it as
Test conditionsclock, own address, DNS
For weekdayRange, dateRange and timeRange. Empty means now.
What Chrome does
How it works
Three steps, none of them on a server
The answers update as you type, so you can change a condition and watch the address move.
01
Paste the PAC file
The whole file, as your browser or your company serves it. The tester reads it with its own JavaScript interpreter and names the line of any mistake.
02
Type the addresses
One per line, up to 50. Each runs through FindProxyForURL with the url and host the browser you picked would hand it.
03
Read the answer and the reason
Every entry of the answer is explained the way that browser reads it, and every call the file made, isInNet, shExpMatch, dnsResolve and the rest, is listed with what it returned.
Chrome and Firefox
One PAC file, two different readings
Read from the browsers' own source code. The biggest one first: neither browser shows the script the path of an https:// address, so a rule that matches on a path fails without a word.
| Chrome | Firefox | |
|---|---|---|
| The url the script receives | https:// addresses without path or query; http:// addresses whole | Every address cut back to scheme://host/ |
| SOCKS with no version | SOCKS4 | SOCKS4 |
| HTTP as a type | Not read: the entry is skipped | Read like PROXY |
| A login inside an entry | The entry is skipped | The login is dropped, the host kept |
| An answer with no readable entry | Connects directly | Skips every entry it cannot read |
| isInNetEx, dnsResolveEx, myIpAddressEx | Available | Not defined: the script fails |
| isPlainHostName | No dot, and not an IPv6 address | No dot and no colon |
Why use it
It runs the file, and shows its work
A PAC file is a program, so the only honest test is to run it, and the only useful one shows why each address went where it went.
It runs your file
The answer comes from executing your FindProxyForURL, line by line, with the PAC functions written the way Chrome and Firefox define them, quirks included: dnsDomainIs is case-sensitive and shExpMatch only knows * and ?.
It shows its work
A PAC file that sends one address the wrong way is usually one condition that never matched. The list of calls shows which one, with the value that made it true or false.
Two browsers, two readings
Chrome and Firefox hand the script a different url and read some answers differently. Switch between them and see whether your file depends on the difference.
Nothing is uploaded
The file runs in your browser, in a separate worker the page can stop, so a loop that never ends costs a message rather than a frozen tab. dnsResolve answers from a list you type instead of asking a DNS server about your hostnames.
Questions
PAC file tester FAQ
What a PAC file is, why one that looks right sends an address the wrong way, and what the tester does with yours.
What is a PAC file?
A proxy auto-config file: a small JavaScript program with one function, FindProxyForURL(url, host), that a browser calls for every address it opens. It returns a string such as PROXY 203.0.113.10:8080; DIRECT, which means try that proxy and connect directly if it fails. Browsers, Windows, macOS, Android and iPhones load it from a web address you give them.
How do I test a PAC file?
Paste it above, type the addresses you care about, one per line, and pick Chrome or Firefox. Each address shows the answer, what every entry in it means and every function the file called on the way. Change the file and the answers update as you type.
Why does my rule for a path never match in Chrome?
Because Chrome does not show the script the path of an https:// address: it passes https://host/ with the path and query removed, and it removes the login and the #fragment from every address. Firefox goes further and passes scheme://host/ for every address. A PAC file that matches on a path only works for plain http:// in Chrome, and never in Firefox. Keep the path shows what the file would do if it saw the full address.
What does SOCKS mean in a PAC file?
SOCKS version 4, in both Chrome and Firefox: the PAC format had only one SOCKS when it was written, and both browsers keep that meaning for compatibility. For a SOCKS5 proxy, write SOCKS5 host:port.
Can a PAC file contain a proxy username and password?
No. Chrome skips an entry with a login in it, and Firefox keeps the address and drops the login. The browser asks for the user name and password itself when the proxy wants them, or your provider can allow your IP address instead.
Does the tester look up DNS?
No. dnsResolve, isResolvable and isInNet with a name answer from the list under Test conditions, so the tester never sends your internal hostnames anywhere. A name that is not on the list does not resolve, and the list of calls says so, so you can add the address a real resolver would give.
Why does myIpAddress return 192.168.1.10?
That is the address under Test conditions, standing in for your computer's own address on its network, which is what a browser returns. Change it to test rules such as isInNet(myIpAddress(), "10.0.0.0", "255.0.0.0").
What happens when FindProxyForURL returns nothing usable?
When the function returns something that is not a string, Chrome reports FindProxyForURL() did not return a string and the tester shows the same. When it returns a string with no entry Chrome can read, Chrome connects directly.
Which functions can a PAC file use?
isPlainHostName, dnsDomainIs, localHostOrDomainIs, isResolvable, isInNet, dnsResolve, convert_addr, myIpAddress, dnsDomainLevels, shExpMatch, weekdayRange, dateRange, timeRange and alert in every browser. Chrome adds dnsResolveEx, isResolvableEx, myIpAddressEx and isInNetEx, which Firefox does not have. The tester runs all of them; pick the browser and it offers exactly that browser's set.
Is my PAC file uploaded?
No. It is read and run by JavaScript in your browser, and the page makes no request with it. You can disconnect from the internet after the page loads and the tester keeps working.
Next
Write one, then check the proxy it sends you to
The setup generator writes a PAC file for your own proxy and the sites to skip; the checkers confirm the traffic really went through it.
Proxy Setup Generator
A PAC file for your own proxy and sites to skip, plus the settings for Windows, macOS, Linux and phones.
Proxy IP Checker
The address that actually reached our server, to confirm the PAC file sent you through the proxy.
Proxy Leak Test
WebRTC, IPv6 and forwarding headers, each with its own verdict, for when the proxy works and sites still recognise you.