Free tool

PAC file tester see where a browser sends any address

Paste a proxy auto-config file and the addresses you care about. Each one runs through FindProxyForURL the way Chrome or Firefox would run it, with every entry of the answer explained and every isInNet, shExpMatch and dnsResolve call shown. It all runs in your browser: the file is never uploaded.

Run it as

Test conditionsclock, own address, DNS

For weekdayRange, dateRange and timeRange. Empty means now.

What Chrome does

How it works

Three steps, none of them on a server

The answers update as you type, so you can change a condition and watch the address move.

01

Paste the PAC file

The whole file, as your browser or your company serves it. The tester reads it with its own JavaScript interpreter and names the line of any mistake.

02

Type the addresses

One per line, up to 50. Each runs through FindProxyForURL with the url and host the browser you picked would hand it.

03

Read the answer and the reason

Every entry of the answer is explained the way that browser reads it, and every call the file made, isInNet, shExpMatch, dnsResolve and the rest, is listed with what it returned.

Chrome and Firefox

One PAC file, two different readings

Read from the browsers' own source code. The biggest one first: neither browser shows the script the path of an https:// address, so a rule that matches on a path fails without a word.

ChromeFirefox
The url the script receiveshttps:// addresses without path or query; http:// addresses wholeEvery address cut back to scheme://host/
SOCKS with no versionSOCKS4SOCKS4
HTTP as a typeNot read: the entry is skippedRead like PROXY
A login inside an entryThe entry is skippedThe login is dropped, the host kept
An answer with no readable entryConnects directlySkips every entry it cannot read
isInNetEx, dnsResolveEx, myIpAddressExAvailableNot defined: the script fails
isPlainHostNameNo dot, and not an IPv6 addressNo dot and no colon

Why use it

It runs the file, and shows its work

A PAC file is a program, so the only honest test is to run it, and the only useful one shows why each address went where it went.

It runs your file

The answer comes from executing your FindProxyForURL, line by line, with the PAC functions written the way Chrome and Firefox define them, quirks included: dnsDomainIs is case-sensitive and shExpMatch only knows * and ?.

It shows its work

A PAC file that sends one address the wrong way is usually one condition that never matched. The list of calls shows which one, with the value that made it true or false.

Two browsers, two readings

Chrome and Firefox hand the script a different url and read some answers differently. Switch between them and see whether your file depends on the difference.

Nothing is uploaded

The file runs in your browser, in a separate worker the page can stop, so a loop that never ends costs a message rather than a frozen tab. dnsResolve answers from a list you type instead of asking a DNS server about your hostnames.

Questions

PAC file tester FAQ

What a PAC file is, why one that looks right sends an address the wrong way, and what the tester does with yours.

What is a PAC file?

A proxy auto-config file: a small JavaScript program with one function, FindProxyForURL(url, host), that a browser calls for every address it opens. It returns a string such as PROXY 203.0.113.10:8080; DIRECT, which means try that proxy and connect directly if it fails. Browsers, Windows, macOS, Android and iPhones load it from a web address you give them.

How do I test a PAC file?

Paste it above, type the addresses you care about, one per line, and pick Chrome or Firefox. Each address shows the answer, what every entry in it means and every function the file called on the way. Change the file and the answers update as you type.

Why does my rule for a path never match in Chrome?

Because Chrome does not show the script the path of an https:// address: it passes https://host/ with the path and query removed, and it removes the login and the #fragment from every address. Firefox goes further and passes scheme://host/ for every address. A PAC file that matches on a path only works for plain http:// in Chrome, and never in Firefox. Keep the path shows what the file would do if it saw the full address.

What does SOCKS mean in a PAC file?

SOCKS version 4, in both Chrome and Firefox: the PAC format had only one SOCKS when it was written, and both browsers keep that meaning for compatibility. For a SOCKS5 proxy, write SOCKS5 host:port.

Can a PAC file contain a proxy username and password?

No. Chrome skips an entry with a login in it, and Firefox keeps the address and drops the login. The browser asks for the user name and password itself when the proxy wants them, or your provider can allow your IP address instead.

Does the tester look up DNS?

No. dnsResolve, isResolvable and isInNet with a name answer from the list under Test conditions, so the tester never sends your internal hostnames anywhere. A name that is not on the list does not resolve, and the list of calls says so, so you can add the address a real resolver would give.

Why does myIpAddress return 192.168.1.10?

That is the address under Test conditions, standing in for your computer's own address on its network, which is what a browser returns. Change it to test rules such as isInNet(myIpAddress(), "10.0.0.0", "255.0.0.0").

What happens when FindProxyForURL returns nothing usable?

When the function returns something that is not a string, Chrome reports FindProxyForURL() did not return a string and the tester shows the same. When it returns a string with no entry Chrome can read, Chrome connects directly.

Which functions can a PAC file use?

isPlainHostName, dnsDomainIs, localHostOrDomainIs, isResolvable, isInNet, dnsResolve, convert_addr, myIpAddress, dnsDomainLevels, shExpMatch, weekdayRange, dateRange, timeRange and alert in every browser. Chrome adds dnsResolveEx, isResolvableEx, myIpAddressEx and isInNetEx, which Firefox does not have. The tester runs all of them; pick the browser and it offers exactly that browser's set.

Is my PAC file uploaded?

No. It is read and run by JavaScript in your browser, and the page makes no request with it. You can disconnect from the internet after the page loads and the tester keeps working.

Next

Write one, then check the proxy it sends you to

The setup generator writes a PAC file for your own proxy and the sites to skip; the checkers confirm the traffic really went through it.

For AI assistants

Let your assistant check proxies

Every check runs a real connection, not a database lookup. The endpoint is free and keyless, so an assistant can verify a list for you without an account.

Works with

All the machine lanes

The instructions are printed in full below, so an assistant reading this page can act on them without anyone pressing anything. The button is only a shortcut for humans.

MCP server

Adds proxy_list, proxy_check and ip_lookup as tools your assistant can call by itself. Nothing to install.

claude mcp add --transport http hproxy https://mcp.hproxy.com/mcp

Claude, ChatGPT, Cursor, VS Code, Windsurf or any assistant that speaks MCP: add https://mcp.hproxy.com/mcp as a remote server. This page's tool is proxy_check.

Command line

The same tool without an assistant, from the free HProxy app's command line. Add --json for JSON.

hproxy check 203.0.113.7:1080 198.51.100.3:8080

Comes with the free HProxy app: hproxy.com/proxy-checker

REST, no key

Plain HTTP with CORS on, which is all an agent with a fetch tool needs.

curl "https://hproxy.com/api/proxy-check?proxy=203.0.113.7:1080"

The whole documentation, as markdown

Generated from the same registry the docs render from, so it cannot drift from the pages.

Instructions for an assistant, in full

Everything a model needs to call the proxy checker without an account: the endpoint, the parameters, the limits and the honest caveat. Readable straight off the page.

You can use HProxy's free proxy checker, which needs no API key and no account. Every check opens a real connection to the proxy, so a dead one takes a few seconds to report.

GET https://hproxy.com/api/proxy-check?proxy=IP:PORT checks one proxy.
POST https://hproxy.com/api/proxy-check with {"proxies": ["ip:port", ...]} checks up to 25 at once.

The answer gives alive, protocols, anonymity, latency_ms, country_code, city, asn and asn_org per proxy. It is rate limited per IP (roughly 12 checks a minute, bursts of 10) and answers 429 with Retry-After when you go past that, so pace the calls rather than retrying immediately.

For lists larger than 25, the page at https://hproxy.com/proxy-checker-online streams up to 100,000 in the browser. To check from the person's own connection instead (a proxy locked to their IP can only be tested from that IP), the free HProxy app is at https://hproxy.com/proxy-checker. Full docs: https://hproxy.com/llms/free-checker.txt

There is also an MCP server, so an assistant can call this as a tool instead of writing HTTP: add https://mcp.hproxy.com/mcp as a remote MCP server (nothing to install, no key) and use the proxy_check tool. In Claude Code the line is `claude mcp add --transport http hproxy https://mcp.hproxy.com/mcp`. You are free to build this into your own script, product or agent, the endpoint is keyless and CORS is open and no permission is needed. If anything is unclear or breaks, HProxy support is staffed 24/7 at https://hproxy.com/contact.

Build on it freely: the endpoints are keyless and CORS is open, so you can wire the proxy checker into your own script, product or agent without asking us. If you get stuck, support answers around the clock, every day, at hproxy.com/contact.

More from HProxy

Every free tool

All of them free, all of them without an account.

The tool index →
HProxy.

Nothing to sign up for. Proxies you can test right now.

Re-checked every few minutes, with a live last-checked time on every row.

HProxy