---
title: "SOCKS5"
url: https://proxy.wiki/glossary/socks5/
type: Glossary Term
author: "proxy.wiki editorial"
published: 2026-08-19
updated: 2026-08-29
site: proxy.wiki
topics: ["Proxy fundamentals"]
license: CC BY 4.0 — quote freely with attribution to https://proxy.wiki/
---

# SOCKS5

> A protocol that proxies any TCP or UDP traffic without inspecting it, defined in RFC 1928.

**SOCKS5 is a general-purpose proxy protocol that forwards traffic at the connection level.** Unlike an HTTP proxy it does not parse or understand what it carries, which makes it usable for any TCP-based protocol and, optionally, UDP.

## What distinguishes it

| Property | SOCKS5 | HTTP proxy |
| --- | --- | --- |
| Traffic it can carry | Any TCP, plus UDP | HTTP and HTTPS tunnels |
| Reads your request | No | Yes, for plain HTTP |
| Can cache | No | Yes |
| Authentication | Username and password, or none | Via [Proxy-Authorization](/glossary/proxy-authentication/) |

## socks5 versus socks5h

This distinction causes real bugs. With `socks5`, your client resolves the hostname locally and sends an address to the proxy — which leaks your DNS queries and can resolve to the wrong regional endpoint. With `socks5h`, the hostname is sent to the proxy and resolved at the far end. For proxy work you almost always want `socks5h`.

## Reference

The protocol is specified in [RFC 1928](https://www.rfc-editor.org/rfc/rfc1928.html), published March 1996.

## SOCKS5 against an HTTP proxy

|  | SOCKS5 | HTTP proxy |
| --- | --- | --- |
| Operates at | The connection layer | The HTTP layer |
| Carries | Any TCP stream, and UDP | HTTP, plus tunnels via [CONNECT](/glossary/http-connect/) |
| Reads your requests | No | Yes, for plain HTTP |
| Modifies headers | Cannot | Often does |
| Authentication | RFC 1929 username and password | Proxy-Authorization header |

The row about headers is the practical one. A SOCKS5 proxy has no concept of an HTTP header, so it cannot add `X-Forwarded-For` or `Via`. That makes it structurally quieter, though the destination still sees everything your client chooses to send.

## The h that changes the behaviour

```
# Your machine resolves the hostname, then sends an address
curl -x socks5://gateway.example:1080 https://example.com

# The proxy resolves the hostname
curl -x socks5h://gateway.example:1080 https://example.com
```

Without the `h` your resolver sees every hostname you request, and you resolve from your own location. Large sites answer differently per region, so you can reach the wrong regional endpoint while the proxy sits in the right country. Prefer `socks5h` unless you have a specific reason not to.

## Frequently asked questions

### Is SOCKS5 more anonymous than an HTTP proxy?

It is quieter by construction, because it cannot add HTTP headers that identify you or the proxy. It is not anonymous in itself: the destination still sees whatever your client sends, and the proxy operator still sees where you connect.

### What is the difference between socks5 and socks5h?

Who resolves the hostname. With socks5 your own machine resolves it and sends an address; with socks5h the proxy resolves it. The first leaks your DNS queries and resolves from your location, which can send you to the wrong regional server.

### Does SOCKS5 support authentication?

Yes, through the username and password method defined in RFC 1929. It is negotiated during the handshake rather than sent as an HTTP header.

## Sources

1. [RFC 1928: SOCKS Protocol Version 5](https://www.rfc-editor.org/rfc/rfc1928.html)
2. [RFC 1929: username and password authentication for SOCKS V5](https://www.rfc-editor.org/rfc/rfc1929.html)
