SOCKS5
A protocol that proxies any TCP or UDP traffic without inspecting it, defined in RFC 1928.
SOCKS5 is a general-purpose proxy protocol that forwards traffic at the connection level. Unlike an HTTP proxy it does not parse or understand what it carries, which makes it usable for any TCP-based protocol and, optionally, UDP.
#What distinguishes it
| Property | SOCKS5 | HTTP proxy |
|---|---|---|
| Traffic it can carry | Any TCP, plus UDP | HTTP and HTTPS tunnels |
| Reads your request | No | Yes, for plain HTTP |
| Can cache | No | Yes |
| Authentication | Username and password, or none | Via Proxy-Authorization |
#socks5 versus socks5h
This distinction causes real bugs. With socks5, your client resolves the hostname locally and sends an address to the proxy — which leaks your DNS queries and can resolve to the wrong regional endpoint. With socks5h, the hostname is sent to the proxy and resolved at the far end. For proxy work you almost always want socks5h.
#Reference
The protocol is specified in RFC 1928, published March 1996.
#SOCKS5 against an HTTP proxy
| SOCKS5 | HTTP proxy | |
|---|---|---|
| Operates at | The connection layer | The HTTP layer |
| Carries | Any TCP stream, and UDP | HTTP, plus tunnels via CONNECT |
| Reads your requests | No | Yes, for plain HTTP |
| Modifies headers | Cannot | Often does |
| Authentication | RFC 1929 username and password | Proxy-Authorization header |
The row about headers is the practical one. A SOCKS5 proxy has no concept of an HTTP header, so it cannot add X-Forwarded-For or Via. That makes it structurally quieter, though the destination still sees everything your client chooses to send.
#The h that changes the behaviour
# Your machine resolves the hostname, then sends an address
curl -x socks5://gateway.example:1080 https://example.com
# The proxy resolves the hostname
curl -x socks5h://gateway.example:1080 https://example.com
Without the h your resolver sees every hostname you request, and you resolve from your own location. Large sites answer differently per region, so you can reach the wrong regional endpoint while the proxy sits in the right country. Prefer socks5h unless you have a specific reason not to.