Made in GermanyISO 27001 certification in progress
Technical Documentation

ProxyTool Documentation

Complete reference for the Windows client, the macOS client, the Android app, and the web dashboard — proxies, chains, rules, DNS, policies and restrictions.

Core Features

Getting Started

ProxyTool is a Windows desktop application that routes your internet traffic through proxy servers at the kernel level. It intercepts connections using a WFP (Windows Filtering Platform) driver, giving you full control over which applications use which proxy — without modifying individual app settings.

Quick Setup (3 Steps)

  • Add a proxy — Enter your proxy server details (host, port, protocol) or paste a proxy string
  • Create a routing rule — Choose which applications or traffic should use the proxy
  • Activate — Traffic is immediately routed through the proxy

Account & Sign-In

ProxyTool uses a unified account for the web dashboard and desktop client. Sign in at /auth/login with email and password. If two-factor authentication is enabled, complete the TOTP or email OTP step before access is granted.

Desktop Sign-In The desktop client opens your browser for login using a secure PKCE flow. After you authenticate, the client receives a one-time token and creates a session — no password is stored locally.
Device Consent Each desktop installation registers as a device on your account. You must confirm adding a new device when your subscription's device limit allows it.
License Slots Your subscription includes a fixed number of device slots (shown in Settings → Subscription and on the web dashboard Devices page). Removing a device frees a slot for another installation.
Web Dashboard Administrators manage fleet devices, policies, and restrictions at /dashboard. See the Web Dashboard section for management documentation.

Dashboard at a Glance

The Dashboard is your central hub — it shows everything happening on your network in real time. Here's what each section does:

Stat Cards Five key metrics at the top: Active Connections, Proxies (online / total), Rules (enabled / total), Data Transfer (sent / received with a progress bar), and Uptime since last start.
Proxies Shows all configured proxies with their protocol badge (SOCKS5, HTTPS, etc.), server address, country flag, latency, and connection status. Click + Add to configure a new one.
Routing Rules Quick view of your active rules — which apps route through which proxy. Toggle rules on/off directly from the dashboard. The Default rule handles all unmatched traffic.
Chains Proxy chains with their type: Simple (sequential), Redundancy (failover), or Load Balancing (round-robin). Shows which proxies are chained together.
Bandwidth Real-time traffic chart showing inbound, outbound, and average throughput over the last 60 seconds. Adjustable refresh interval (1s–10s).
Live Connections Table of all active connections with process name (chrome.exe, msedge.exe, etc.), target domain, connection time, matched rule, proxy used, and bytes sent/received. Use Freeze to pause the live feed.
Live Log Stream Detailed event log with verbosity filters (Normal, Verbose, Debug, Error) and source filters (All, Backend, Connections). Shows TCP open/close events, proxy handshakes, DNS resolutions, and error details. Toggle Follow: On to auto-scroll.

Customize Your Dashboard

Click Customize in the top-right corner to enter edit mode. A toolbar appears at the top of the dashboard where you can control every section individually.

Stat Cards

Toggle each metric card on or off — disabled cards are hidden from the dashboard entirely.

CardShows
ProcessedTotal connections handled in the current session
ProxiesOnline proxies vs. total configured (e.g. 2 / 2 online)
RulesEnabled routing rules vs. total (e.g. 2 / 3 enabled)
Data TransferTotal bytes sent and received with a progress bar
UptimeTime since ProxyTool was started (e.g. 1d 21h 6m)

Widget Panels

Each widget panel represents a major dashboard section. Disable panels you don't need to keep things focused.

PanelContent
My ProxiesQuick overview of all configured proxy servers with status and latency
Traffic ChartReal-time bandwidth graph with in/out/average throughput
Live ConnectionsActive connection table with process, target, proxy, and transfer data
Routing RulesRule cards with on/off toggles and assigned proxy details
ChainsProxy chain configurations (Simple, Redundancy, Load Balancing)
Live LogsReal-time event log with verbosity and source filters

Layout Options

  • Connections Height — Choose between 280px, 400px, 520px, 640px, or 760px to control how many connection rows are visible without scrolling
  • Reorder — Drag the arrow handles between stat cards to rearrange their order
  • Fine-tuning — Drag the grip under the Connections panel to adjust its height precisely

Click Done to save your layout. Use Reset All to restore the default arrangement, or Clear to remove all customizations and start fresh.

ProxyTool requires Windows 10+ (64-bit) on an Intel or AMD processor — ARM devices such as Snapdragon-based Copilot+ PCs or the Surface Pro X are not supported yet, a native ARM build is coming. Administrator privileges are needed for the kernel driver. The driver is EV code-signed — Windows SmartScreen will not show an unknown publisher warning.

Adding a Proxy

Click Add Proxy on the Proxies page to open the configuration dialog. You can either fill in fields manually or paste a proxy string for instant setup.

Server Details

These fields are identical for every proxy type. Enter address details manually or use Quick Add: paste a proxy string (e.g. socks5://host:port:user:pass) or a curl -x command and all fields auto-fill instantly.

Proxy Name Display name or Quick Add string. Supports formats from providers like Evomi, Thordata, and others.
Host Address IP address or hostname of the proxy server.
Port Port number (1–65535). 8080
Proxy Type Protocol selector — HTTP, HTTPS, SOCKS4, or SOCKS5. The options panel below changes based on this selection.

Options by Protocol

The options shown below the protocol selector differ depending on the type you choose. Use the carousel tabs above to compare each protocol side by side.

Options Panel at a Glance
Option HTTP / HTTPS SOCKS4 SOCKS5
Requires Authentication Username + Password + Method selector (Basic / NTLM / Negotiate) N/A — replaced by User Identification Username + Password (auto-negotiated)
User Identification N/A User ID string (ident-based access, no password) N/A
SOCKS4a Extension N/A Toggle — enables remote DNS via proxy N/A (remote DNS built-in)
Send User-Agent Toggle — sends browser User-Agent header in CONNECT requests N/A N/A
Cost per GB Yes Yes Yes
Advanced Options Yes Yes Yes

Authentication Details

Toggle Requires Authentication (or User Identification for SOCKS4) to reveal credential fields. The layout changes per protocol:

Authentication by Protocol
Feature HTTP / HTTPS SOCKS4 SOCKS5
Credential fields Username + Password User ID only (no password) Username + Password
Auth method Basic, NTLM, or Negotiate (Kerberos) — dropdown selector N/A — ident string sent with CONNECT N/A — method auto-negotiated (RFC 1929)
Use Current User Login Yes (NTLM/Negotiate — uses Windows SSPI credentials) N/A N/A

Send User-Agent (HTTP / HTTPS only)

When enabled, ProxyTool adds a User-Agent header to the HTTP CONNECT handshake. Some proxies require this to allow the connection. A default Chrome 131 string is pre-filled, but you can set any custom value. This option does not appear for SOCKS4 or SOCKS5 because these protocols do not use HTTP headers.

SOCKS4a Extension (SOCKS4 only)

Standard SOCKS4 resolves hostnames locally before forwarding — which leaks DNS queries. With SOCKS4a enabled, the hostname is sent to the proxy for remote resolution, keeping your DNS private.

How SOCKS4a remote DNS works

ProxyTool sends a dummy IP (0.0.0.1) along with the target hostname. The proxy resolves the hostname on its end — your local DNS never sees the domain name.

ModeDNS ResolutionPrivacy
SOCKS4 (off)Client resolves locally to IPv4DNS visible to ISP
SOCKS4a (on)Proxy resolves remotelyDNS hidden from ISP

Cost per GB

Available for all protocol types. Enter your cost rate (e.g. $2.50 /GB) to enable real-time cost tracking in the Connection Monitor — especially useful for residential or metered proxies.

Advanced Proxy Settings

Expand the Advanced Options section in the Add Proxy dialog to access these settings. They apply to all proxy types unless noted.

Add Proxy — Advanced Options expanded: Ask Credentials, Authentication URL, Use Target Hostname Advanced Options expanded — auth prompts, authentication URL, and Use Target Hostname
Option Default What it does
Ask Credentials if Empty On Shows an interactive login prompt at connect time if no credentials are saved for this proxy
Ask Credentials if Auth Fails On Re-prompts for credentials when the proxy rejects authentication (HTTP 407, SOCKS rejection)
Use Authentication URL Off Authenticate via a URL instead of stored credentials. Used for enterprise proxies (e.g. Blue Coat) that use web-based auth portals
Authentication URL The URL to use for authentication. Supports embedded credentials: scheme://user:pass@host. Required when the toggle is enabled
Use Target Hostname Off Sends the original hostname (not resolved IP) in the proxy CONNECT request. Useful when the proxy needs to see domain names for routing or logging
When Use Authentication URL is enabled, the credential prompt options are automatically disabled and stored username/password are cleared — the URL handles all auth at runtime.

Inline Proxy Checker

Before saving, click Check to verify connectivity. The checker runs a multi-step test against a configurable target (default: google.com):

  • Proxy connection — TCP connect to the proxy server, measures latency
  • HTTPS handshake — Sends the CONNECT request to the proxy
  • Authentication — Handles proxy auth (407 response → sends credentials)
  • Credential check — Verifies credentials were accepted (HTTP 200)
  • Target connection — Reaches the target through the proxy end-to-end

All steps show a green checkmark on success with detailed status messages. The total latency is displayed at the top right (e.g. 99 ms), and a summary line confirms the result: PASSED — All tests OK.

Proxy Checker — 5 steps passed: Proxy connection, HTTPS handshake, Authentication, Credential check, Target connection (99ms) Inline Proxy Checker — all 5 tests passed (99 ms latency) with target google.com

Managing Proxies

The Proxies page displays all configured proxy servers in a sortable table with real-time status indicators.

Proxies page showing proxy table with status, latency, location, and action controls Proxies — Server list with protocol, address, location, latency, and quick actions

Table Columns

Column Shows
Name Display name you assigned
Type Protocol badge (HTTP, HTTPS, SOCKS4, SOCKS5)
Address host:port
Location Country flag + city (auto-detected via GeoIP lookup)
Status Active (green dot) or Inactive (gray dot)
Latency Response time in ms, color-coded (green/yellow/red)
Actions Toggle on/off, Edit, Delete, Test

Filters & Search

  • Search — Filter by name, address, or location
  • Type filter — All / HTTP / HTTPS / SOCKS4 / SOCKS5
  • Status filter — All / Active / Inactive

Actions

  • Toggle — Activates/deactivates the proxy (starts or stops the bridge)
  • Edit — Reopens the Add Proxy dialog in edit mode with all fields pre-filled
  • Delete — Stops the proxy if active, then removes it. Shows a warning if the proxy is used in chains or rules
  • Test — Runs the connectivity checker without opening the dialog
Newly added proxies start as inactive. They only route traffic when activated directly or referenced by an active routing rule.

Routing Rules

Rules determine which traffic goes through which proxy (or chain), goes direct, or gets blocked. They are evaluated top-to-bottom by priority — the first matching rule wins. Click + Add Rule to open the configuration dialog.

Rules Overview

The Rules page lists all configured routing rules with their priority number, action badge (Proxy / Direct / Block), on/off toggle, and summary tags showing matched apps, hosts, ports, and protocol. Use the up/down arrows on the right to reorder priorities — the first matching rule wins.

Rule Setup

The top half of the dialog defines what traffic this rule matches. All four criteria are optional — leave a field empty (or *) to match everything.

Field Format Examples
Rule Name Descriptive label Google Services, Dev Server
Application / Process Name, path, wildcards (*, ?), multiple separated by ;. Use Browse to pick an EXE. chrome.exe; msedge.exe, *bin*, pid=1234
Target Hosts Domain patterns, comma-separated. * = all hosts. *.google.com, api.example.org
Target Ports Numbers, comma-separated. * = all ports. 80,443,8080

Protocol

Select which transport protocol this rule applies to. The dropdown offers TCP, UDP, or BOTH. Note that UDP routing requires a SOCKS5 proxy — HTTP and SOCKS4 proxies only support TCP.

Debugging UDP traffic: Enable Traffic Dump under Settings → General → Diagnostics to capture detailed .dmp logs of all proxied TCP and UDP connections. Useful for verifying that game, VoIP, or streaming traffic is actually routed through your proxy.

Actions

The Action dropdown defines how matched traffic is routed. Each action type shows different follow-up options:

Action Types at a Glance
Action What it does Follow-up options
Direct Bypass proxy — traffic goes straight to the destination Priority, Enable toggle
Proxy Route through a specific proxy server Proxy selector (shows all configured servers with protocol badge), Protocol (TCP/UDP/BOTH), Priority, Enable toggle, Advanced Options
Chain Route through a proxy chain Chain selector (shows all configured chains), Priority, Enable toggle, Advanced Options
Block Drop the connection — app receives connection refused Priority, Enable toggle

When selecting Proxy, the dropdown lists all configured servers with their protocol badge (HTTPS, SOCKS5). When selecting Chain, you choose from your configured chain setups (Load Balancing, Redundancy, Simple).

Priority & Enable

Every rule has a Priority level (1 = lowest, 10 = highest). Higher priority rules are evaluated first. The Enable this rule immediately toggle (on by default) activates the rule right after creation — disable it to save a rule for later use.

Advanced Routing Options

Expand Advanced Options at the bottom of the Add Rule dialog (available for Proxy and Chain actions) to access network interface control and IPv6 settings.

Option Default Description
Outgoing Interface Automatic Interface Force this rule's traffic through a specific network adapter (e.g. WiFi, Ethernet, VPN). Automatic lets the OS decide.
IPv6 through proxy Off Off: IPv6 connections are dropped and logged to the leak-prevention log. On: IPv6 traffic is forwarded through the rule's proxy or chain.
UDP/QUIC note: When using TCP-only proxies (HTTP or SOCKS4), UDP traffic from matched applications (including QUIC/HTTP3 and WebRTC) will be dropped if "Block unsafe UDP fallback" is enabled in DNS settings. Only SOCKS5 supports UDP relay.

Proxy Chains

Proxy chains combine multiple proxies into a single routing target. ProxyTool supports three chain types — Simple (sequential multi-hop), Redundancy (automatic failover), and Load Balancing (random distribution). Click + Add Chain to open the configuration dialog.

Chains Overview

The Chains page lists all configured chains with their type badge (Simple, Load Balancing, Redundancy), proxy count, and a route visualization showing the traffic path (e.g. Static Test Proxy → TestProxy1). Expand a chain to see per-proxy health status with test results and latency.

You need at least 2 proxies configured before you can create a chain. Chains are activated by assigning them to a routing rule — they don't have their own on/off toggle.

Chain Setup

Enter a Chain Name, then select one of the three chain types. Each type shows its own configuration options below the selector. The Available Proxies panel lists all configured proxy servers — click the + button next to a proxy to add it to the chain.

Chain Type Comparison
Aspect Simple Redundancy Load Balancing
How it works All proxies in sequence (multi-hop) One proxy at a time (failover) Random proxy per connection
Traffic flow Client → A → B → Target Client → first working proxy → Target Client → random proxy → Target
Use case Multi-hop anonymity High availability / backup proxies IP rotation / load distribution
On failure Whole chain fails Tries next proxy in order Excludes failed proxy from pool
Order matters? Yes — defines hop sequence Yes — defines failover priority No — random selection from pool

Simple Sequential Chain

Routes traffic through every proxy in order as a true multi-hop chain. Each proxy becomes a hop between your device and the destination. Adds latency but increases anonymity. The order you set in the Chain Order section determines the hop sequence.

HTTP/HTTPS proxies may only be the last hop in a Simple chain. Earlier hops must be SOCKS4 or SOCKS5 due to protocol limitations.

Redundancy Failover Chain

Uses one proxy at a time from the ordered list. Tries the first enabled proxy; if it fails validation within the timeout, automatically switches to the next.

Option Default Description
Connection Timeout 10s How long to wait before declaring a proxy failed. Adjustable with + / buttons (1–120 seconds).
Connect directly if all fail Off On: bypass proxies entirely when all fail. Off: block the connection.
Recheck failed proxies 300s Background timer re-tests failed proxies automatically. Set to 0 to disable.

Load Balancing Random Distribution

Distributes connections across multiple parallel proxies. Each new connection gets assigned a random proxy from the pool.

Option Default Description
Same proxy for same process (PID) Off Off: rotate proxy per connection (even within the same app). On: lock one proxy per process for session stickiness.
Use PID stickiness when an application needs a stable IP (e.g. logged-in sessions) but you still want different apps to use different proxies from the pool.

Creating a Chain

Steps

  • 1. Name your chain — Enter a descriptive name (e.g. "Secure Multi-Hop")
  • 2. Select chain type — Simple, Redundancy, or Load Balancing — each shows its own configuration options
  • 3. Add proxies — Click the + button next to a proxy in the "Available Proxies" panel. Proxies show their protocol badge (HTTPS, SOCKS5) and can only appear once per chain.
  • 4. Set order — In the Chain Order section, use the ▲ ▼ arrow buttons to move proxies up or down. Traffic flows top to bottom. Click to remove a proxy from the chain.
  • 5. Configure options — Set type-specific options (timeout for Redundancy, PID stickiness for Load Balancing)
  • 6. Save — Click Add Chain. Assign the chain to a routing rule to start using it.

Redundancy (failover)

Pick Redundancy to try proxies in priority order. Configure connection timeout, optional direct fallback, and how often failed hops are rechecked.

Redundancy chain — Failover Options: Connection timeout, Connect directly, Recheck timer Redundancy — failover timeout, direct fallback, and recheck timer

Load Balancing

Pick Load Balancing to distribute connections across the pool. Enable Same proxy for same process (PID) when an app needs a stable IP for its session.

Load Balancing chain — Same proxy for same process (PID) toggle, Available Proxies Load Balancing — PID stickiness and available proxies

Adding proxies to the chain

In Available Proxies, click + next to each hop. They appear in Chain Order where you can reorder or remove them.

Available Proxies — click + to add HTTPS or SOCKS5 servers to the chain Available Proxies — add hops with the + button
Chain Order — numbered proxies with up/down reorder and remove Chain Order — numbered hops with reorder arrows

Chain Order

The Chain Order section shows all added proxies as numbered cards. Each card displays the proxy name, address, and protocol badge. Use the (up) and (down) arrow buttons to reorder — traffic flows from position 1 downward. A visual arrow connects the hops to illustrate the routing path. The counter (e.g. 2 proxies) shows how many are in the chain, with a minimum of 2 required.

Chain List Features

  • Type badge — Color-coded: Simple, Load Balancing, Redundancy
  • Route visualization — Shows the proxy flow: Proxy A → Proxy B → ...
  • Per-proxy health — Expand a chain to see individual proxy test results with latency, e.g. PASSED — All tests OK (98 ms)
  • Edit / Delete — Edit reopens the dialog, Delete removes the chain. Shows a warning if the chain is used in routing rules.

DNS & Name Resolution

The DNS page controls how hostnames are resolved and provides leak-prevention features that keep your real IP address hidden. Three tabs at the top let you switch between detection modes, while the settings below fine-tune privacy behaviour.

Current DNS Mode

The status badge in the top-right corner (Local DNS or Via Proxy) shows the active resolution path at a glance. Three tabs below it control the detection mode:

Tab How it works Best for
Automatic Detection Monitors network conditions and switches to proxy DNS automatically when local DNS is unavailable General use — best balance of speed and privacy
Local Resolution Always uses the system's own DNS resolver Performance priority — fastest resolution
Exclude / Name List Fine-tune which domains bypass proxy DNS. Supports wildcards (*, ?) and constants like %ComputerName% Hybrid setups where some domains must resolve locally

Proxifier DNS Settings

Two toggles control the connection between auto-detection and proxy resolution:

  • Detect DNS settings automatically — monitors network conditions and switches DNS mode when local DNS becomes unavailable (on by default)
  • Resolve hostnames through proxy — sends all DNS queries through the proxy server instead of local DNS. When enabled, the badge changes to Via Proxy and the detection tab switches to Manual / Proxy
Privacy note: When using "Resolve via proxy", ProxyTool may still need to resolve your proxy endpoint hostname locally. This does not reveal the websites you visit, but your local DNS may see the proxy provider domain. To avoid this, configure the proxy using an IP address instead of a hostname.

IP Protection & Leak Prevention

IP Protection panel with UDP fallback, IPv6, and Strict DNS toggles

Scroll down on the DNS page to find the IP Protection panel. These settings prevent traffic from leaking outside the proxy when the operating system or applications attempt alternative network paths. You can enable everything at once or pick individual modules in custom mode.

Option Default What it prevents
Enable all IP protection Off Master toggle — activates all protection modules below and locks them on
Block unsafe UDP fallback Off Blocks direct UDP connections (incl. QUIC/HTTP3 and WebRTC) when a rule requires proxying but the route cannot carry UDP
Protect IPv6 UDP paths Off Blocks IPv6 UDP traffic that is not currently kept on a safe proxy relay path
Strict DNS over proxy Off If DNS should go through the proxy, blocks unsupported query types or missing safe paths instead of allowing direct fallback
Custom mode: When the master toggle is off, the info banner reads "Custom mode: you can enable only the protection modules you want." Toggle each option individually to match your privacy requirements.
Windows Smart Multi-Homed Name Resolution (SMHNR)

Windows may send DNS queries across all available network interfaces simultaneously (Smart Multi-Homed Name Resolution), which can bypass proxy DNS even when "Resolve via proxy" is enabled.

When IP Protection or Strict DNS is active, ProxyTool warns about this. To switch SMHNR off system-wide, open Command Prompt as Administrator and run both commands:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v DisableSmartNameResolution /t REG_DWORD /d 1 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters" /v DisableParallelAandAAAA /t REG_DWORD /d 1 /f

Then restart Windows. The DNS Client service (Dnscache) cannot be restarted on its own on Windows 10 and 11, so a reboot is what applies both values. Missing keys are created by reg add, so the commands also work on a machine where the DNSClient key does not exist yet.

What the two values change:

  • DisableSmartNameResolution — stops Windows from issuing DNS, LLMNR and NetBIOS queries across every interface at once. This is the same value that the group policy Computer Configuration → Administrative Templates → Network → DNS Client → Turn off smart multi-homed name resolution writes, so on Windows Pro and Enterprise you can use gpedit.msc instead of the command.
  • DisableParallelAandAAAA — stops A and AAAA lookups from running in parallel across all configured DNS servers, where the fastest answer wins and an IPv6 lookup can slip past the proxy path.

ProxyTool's DNS page shows the same two settings as PowerShell Set-ItemProperty commands. To undo the change, run the commands again with /d 0 and restart Windows.

Additionally, disable browser Secure DNS (DoH) to prevent browsers from resolving names independently.

Traffic Monitor

The Traffic Monitor page is your real-time command center for network visibility. Two tabs at the top — Analytics and Connections — let you switch between high-level insights and a detailed connection table. Use Freeze to pause all counters for analysis, or Clear to reset session data.

Summary Cards

Four cards at the top provide session-level metrics at a glance:

Active Connections Current number of open connections this session
Total Sent / Received Cumulative bytes with real-time upload/download speed indicators
Bandwidth Combined traffic total with upload and download speed

Analytics Tab

The Analytics tab organizes traffic data into several cards that scroll vertically:

Card What it shows
Traffic Monitor Per-app bandwidth bars (e.g. Chrome 1.9 MB, MS Edge 2.4 MB) with total and primary proxy name
Protection Overview Ring chart showing proxied vs. direct ratio (e.g. 100% Protected), geo-badges (DE, US), and a privacy assessment
Proxy Usage Stacked bar with traffic distribution across proxies (e.g. TestProxy1 76%, Static Test Proxy 24%, Direct 0%)
Security Shield Threats Blocked + Conn Errors counters. Click any event to expand Connection Flow details: process path, host, IP, proxy route, bytes sent/received, and a diagnosis (e.g. "Proxy handshake failed")
Proxy Health Per-proxy quality score ring (0–100), connection count, error rate, average duration, and traffic volume
Domain Intelligence DNS-based category ring (Google, Microsoft, Tracking, Streaming, Cloud, Other) with per-domain breakdown showing request count and traffic percentage
Protocol Insights TCP/UDP split, TLS encryption ratio, DNS virtualization percentage, DNS leaks blocked, IPv4/IPv6 balance, UDP relay status, and session history

Connections Tab

Connections table with process, target, time, rule/proxy, sent/received

The Connections tab shows a live table of every active and recent connection:

Column Shows
Process Application name + PID (e.g. chrome.exe PID: 800)
Target Hostname and resolved IP with port
Starts Connection start time
Time Connection duration (or "Closed" for finished connections)
Rule / Proxy Which rule matched and the full proxy route (e.g. "Static Test Proxy • isp-2.evomi.com:12345 HTTP")
Sent / Recv Bytes transferred in each direction

Connection Forensics

Scroll down in the Connections tab to find Connection Forensics. Two sub-tabs — Domains and By Proxy — provide deep analysis:

  • Domains — Shows all contacted domains with request count and traffic percentage. The overall block rate is displayed in the header
  • By Proxy — Expand each proxy to see success rate, block rate, wasted data, and blocked domains with frequency

Cost Overview

The Cost Overview card calculates real-time proxy expenses based on the per-GB rate you set on each proxy. The total cost badge (e.g. $0.2298 total) appears in the top-right corner. Four tabs let you slice the data differently:

  • Overview — Unified ranking of all proxies, processes, and domains sorted by traffic. Each entry shows a type badge (Proxy / Process / Domain), traffic volume, and cost
  • By Proxy — Traffic and cost per proxy endpoint with connection count breakdown
  • By Domain — Ranked list of domains by traffic, useful for identifying bandwidth-heavy sites
  • By Process — Per-application cost breakdown so you can see which processes generate the most proxy traffic

Cost Optimization

The Cost Optimization card identifies wasted proxy traffic — connections that were blocked or failed (RST) but still consumed bandwidth. The badge (e.g. $0.0002 wasted) highlights the total wasted cost. Click any entry to expand details:

  • Overview — Ranked list of domains with wasted bytes, associated proxy and process, and cost per entry
  • By Proxy — Click a proxy to see its top wasted domains and processes. Shows total block count, success rate, and block rate per proxy
  • By Domain — Wasted traffic grouped by domain name
  • By Process — Wasted traffic grouped by application (e.g. msedge.exe, chrome.exe)
RST classification: RST <500ms = IP blocked • FIN <300ms = soft-block/captcha • Normal RST after >2s = healthy TCP cleanup. This helps distinguish actual blocks from normal connection teardown.

TLS Fingerprint Detection

ProxyTool monitors TLS Client Hello packets and compares JA3 fingerprint hashes against a known database. When a connection's fingerprint indicates a potentially detectable automation tool, a warning card appears in the Analytics tab with fix suggestions.

TLS Fingerprint Warning — curl.exe detected as DETECTABLE with fix suggestion

In this example, curl.exe was flagged as DETECTABLE because its TLS fingerprint does not match any known browser. The warning card explains that anti-bot systems like Cloudflare, Akamai, and DataDome compare JA3 hashes against known browsers, and suggests using curl_cffi, Camoufox, or Playwright with stealth plugins instead.

TLS Risk Levels
Risk Fingerprint Source Badge Action
Low Chrome, Firefox, Safari, Edge (real browsers) No warning Normal browser-like traffic — no detection risk
Medium Playwright, Puppeteer, Selenium, curl_cffi, Camoufox DETECTABLE Destination may flag as automation — consider fingerprint masking
High Python requests, curl, Go net/http, Java HttpClient, wget, Scrapy BLOCKED Known bot fingerprint — likely blocked by anti-bot services

The warning panel shows: process name, number of flagged connections, affected domains (last 5), and process-specific suggestions for fixing the fingerprint.

ProxyTool does not modify your TLS fingerprint. The warning is purely informational — it tells you what a destination server could detect based on the client's TLS handshake pattern.

Cost Tracking

If you've configured a Cost per GB rate on your proxies, the Monitoring page calculates real-time spending based on actual traffic.

How Cost Is Calculated

cost = (bytes_transferred / 1,073,741,824) × cost_per_gb
  • Calculated per proxy based on the rate set in the proxy's configuration
  • Includes both upload and download bytes
  • Displayed with up to 6 decimal places for precision on small transfers
  • Visible in Security Shield events and the Cost Optimization card

Cost Optimization

When you have at least 5 proxied connections, the analytics tab shows a Cost Optimization card that breaks down wasted bandwidth by proxy, domain, and process — helping you identify where to reduce costs.

Application Settings

The Settings page provides centralized control over subscription management, appearance, system behavior, privacy, and diagnostics. A search bar at the top filters settings in real time — type any keyword to locate and navigate directly to the matching setting.

Settings Search

The search bar at the top of the Settings page provides instant filtering. Typing a keyword (e.g. "tray", "DNS", "encryption") highlights and scrolls to the matching setting, making it easy to locate options without browsing through tabs.

Subscription

Setting Description
Current Plan Displays the active subscription tier (Free, Pro, etc.) and expiration date
Device Management Shows the number of device slots used vs. available. Displays a warning when the device limit is reached
Sync Status Indicates whether profile and settings are synced with the cloud account
User Account Shows account name and email. Provides a Logout button to disconnect the device from the account

General

Setting Default Description
Theme System Light or Dark appearance
Language English English or Deutsch
System Tray Icon On Show ProxyTool icon in the notification area
Minimize to Tray On Close button minimizes to tray instead of quitting
Desktop Notifications On Show system notifications for connection events
Show Traffic on Tray Icon On Display live upload/download activity on the tray icon
Show Direct Connections On Include bypassed (direct) traffic in logs and monitoring

Safety

Setting Default Description
Connection Loop Detection On Detects and blocks runaway proxy redirection loops
DNS Resolution Loop Detection On Detects DNS-over-proxy loops and auto-disables proxy DNS to prevent lockout

Diagnostics

Setting Default Description
Traffic Dump Off Save proxied TCP traffic as .dmp files for debugging. Warns when files exceed 1000 or 500 MB total

Profiles & Migration

Profiles save your complete configuration (proxies, chains, rules, DNS settings) as portable .ppx files. You can maintain multiple profiles and switch between them.

Active Profile

The current workspace is auto-saved continuously. To persist a configuration as a named profile, use Save As. The active profile name is displayed at the top of the Profiles tab. Additional controls include:

  • New Blank — Reset to a clean empty configuration
  • Save As — Save current workspace as a named profile
  • Import — Load a .ppx file from disk (or a Proxifier .ppx/.xml)
  • Export — Save the current configuration to a file for sharing or backup

Saved Profiles

All saved profiles appear in a list below the active profile. Each entry shows the profile name and provides Load and Delete actions. The currently active profile is highlighted. Loading a profile replaces the entire active workspace configuration.

Profile Auto Update

Profiles can be fetched automatically from a remote server. This is useful for team deployments or managed environments where configuration changes need to propagate to all devices.

Setting Description
Auto Update Toggle Enable or disable automatic profile fetching at startup
URL Remote URL pointing to a .ppx file or a folder containing multiple profiles
Update Mode Dropdown to select update behavior (e.g. replace entire profile, merge additions only)
Keep Credentials When enabled, existing proxy passwords are preserved during the update
Update Now / Stop Manually trigger an immediate update or cancel an in-progress fetch
If the auto-update URL uses HTTP (not HTTPS), passwords in the downloaded profile travel in clear text over the network. The UI displays a yellow security warning when an insecure URL is configured.

Password Encryption

Profile files can encrypt stored proxy passwords using one of four modes. The encryption mode selector is a radio button group in the Profiles tab.

Mode Security Level Notes
Disabled None Passwords stored as plain text in profile
Basic Windows only Superseded by This Device Only and no longer offered on macOS or Linux. On Windows it is the same DPAPI as This Device Only; on the other platforms it stores the passwords unencrypted, so existing profiles are still read but nothing new is written with it
This Device Only High Encrypted with a key the operating system keeps for this user account: DPAPI on Windows, the keychain on macOS, the desktop keyring on Linux. A copied profile cannot be decrypted on any other machine or by any other user
Master Password Highest Key derived from a user-chosen master password over 100,000 HMAC-SHA256 rounds. The only mode every ProxyTool client can read, and portable between devices; the password is required each time the profile is loaded

Profile Files

Profiles are stored as XML .ppx files. The Profiles tab shows the user profile directory path with a copy button for quick access in file explorer.

  • User profile directory — Default location where named profiles are saved
  • Default.ppx — Place this file in the application directory or C:\ProgramData\ProxyTool\ to auto-load a profile for all users on the machine
  • CLI loading — Run ProxyTool.exe profile.ppx [silent-load] to load a specific profile at launch. The silent-load flag suppresses the load confirmation dialog
Editing an existing proxy reopens the same Add Proxy dialog with all fields pre-filled, so you can adjust any setting without re-entering everything from scratch.

Migrate from Proxifier

ProxyTool can import your existing Proxifier configuration (.ppx / .xml) including proxy servers, chains, rules, DNS settings, and leak-protection options. The import wizard detects all components and guides you through any manual steps required.

What It Imports

  • Proxy servers — Host, port, protocol, and authentication credentials
  • Proxification rules — Application-based routing rules (process name → proxy assignment)
  • Proxy chains — Multi-hop configurations and failover setups
  • DNS settings — Name resolution preferences from the Proxifier profile
  • Leak-protection options — UDP blocking and related privacy settings

Encryption Handling

Proxifier profiles may store proxy passwords using different encryption methods. ProxyTool detects the encryption mode and handles decryption automatically when possible:

Encryption Mode Auto-Decrypt Details
Basic (Static Key) Not yet Proxifier uses a built-in static key. Auto-decryption support is planned; use Password Manager for now
Current User Account (DPAPI) Yes* Automatically decrypted if importing on the same Windows user account that created the Proxifier profile. Fails on a different PC or user — use Password Manager
Master Password Not yet Requires the original master password. Auto-decryption support is planned; use Password Manager for now
When DPAPI decryption fails (different PC or user account), the import wizard displays a DPAPI warning and opens the Password Manager so you can manually enter the passwords.

Password Manager Workflow

The Password Manager appears inside the import modal when automatic decryption is not available. It provides a bulk interface for entering proxy passwords:

  • Proxy selection — Select individual proxies via checkboxes, or use the header checkbox to select all
  • "All same" bulk-apply — Enter one password and apply it to all selected proxies at once
  • Per-proxy fields — Individual password input fields for each proxy that needs credentials
  • Apply button — Commits the entered passwords to the import configuration
  • Progress badge — Shows completion status (e.g. "0/3") indicating how many proxies still need passwords

After Import

Imported items are added to the current active configuration. Proxies, chains, rules, and settings merge into the workspace immediately. To persist the imported configuration as a named profile, use Save As in the Profiles tab.

The final review screen lists all detected proxies, rules, and settings before committing. Use the Cancel button to abort without changes, or Import to apply everything to the current workspace.

AI Configuration Assistant

The Assistant page in the desktop client turns a sentence into a configuration change. You describe what you want — "route Discord through my US proxy", "block Steam", "chain these two proxies" — and the assistant replies with an explanation plus the concrete changes it proposes, shown as cards below the answer.

Nothing is applied on its own. Every proposed change sits on a card with an Apply button, and a response with several changes adds an Apply All button. Until you click, your configuration is untouched.

Step by step in the client

  • 1. Open the page — Click Assistant in the left sidebar of the desktop client. The start screen shows three shortcuts: Route Discord sends that request straight away, Parse Proxy String puts the cursor in the input, and Analyze Screenshot opens the file picker.
  • 2. Describe what you want — Type into the message box at the bottom, for example "Route Discord through my Evomi proxy" or paste a proxy string such as socks5://user:pass@host:1080. Enter sends, Shift+Enter starts a new line. If you are unsure of an executable name, open the App Catalog, search for the program and click it — its name is inserted into your message.
  • 3. Add a screenshot (optional) — Click the image button next to the input or press Ctrl+V with a screenshot in the clipboard. An Image attached chip appears above the input and can be removed before sending.
  • 4. Wait for the answer — While the request runs, the input is locked and the client shows "ProxyTool AI is thinking…". A typical answer takes a few seconds.
  • 5. Read the reply and its cards — Below the text answer, every proposed change appears as its own card with an icon and a short summary, for example Rule created (6 Apps) or Proxy updated. The chat text is selectable, so you can copy it with Ctrl+C.
  • 6. Apply what you want — Click Apply on a single card, or Apply All (n) above the group to take everything at once. Applied cards turn green with a past-tense label and cannot be applied twice; the header switches to All applied (n) once nothing is left.
  • 7. Check the result — The change lands in the client immediately. Open Proxies, Routing Rules or Proxy Chains to see it in the normal editors, where you can fine-tune or delete it by hand like any other entry.
The assistant prefers fewer, broader rules. Asking it to "route all browsers" produces one rule listing chrome.exe, firefox.exe, msedge.exe and the rest, not six separate ones. If you want them split, say so in the message.

Chats, history and the credit badge

  • New Chat — Starts a fresh conversation. The previous one is saved automatically and titled after your first message.
  • History list — Past chats sit in the panel on the left with a relative timestamp (just now, 2h ago, yesterday). Click one to reopen it, or delete it there. The client reopens your last chat the next time you start it.
  • Stored locally — Conversations live in the client's own settings on that machine. They are not synced to the web dashboard and not kept on our servers.
  • Credit badge — The header shows your remaining AI credits and refreshes each time you open the page. When the balance is empty it reads No Credits and the assistant replies with an upgrade note instead of running the request.
  • Restricted by an admin — If your organisation blocked AI use, the page shows "AI Assistant has been restricted by your administrator" and the input is hidden. If the whole page was hidden, the sidebar entry disappears. See Device Restrictions.

What it can change

AreaWhat the assistant can do
ProxiesAdd a proxy server, edit an existing one, or update all proxies at once — for example when a provider changes your password
Routing RulesCreate, edit and delete rules, enable or disable them, and change advanced rule options
Proxy ChainsCreate, edit and delete chains, and assign a chain to a rule
SettingsDNS behaviour, IP leak protection and logging options

What the assistant knows about your setup

So that answers fit your actual configuration, a short summary of the current workspace is sent with every message:

ProxiesUp to 10 entries with name, host, port, protocol and username — never passwords
ChainsAll chains with their type and options
RulesUp to 10 rules with apps, action, protocol, assigned proxy or chain, and whether they are enabled
SettingsCurrent DNS, IP protection and logging state

Screenshots

You can attach an image with the paperclip button or paste one with Ctrl+V — an error dialog from an app that refuses to connect, for instance. Accepted formats are PNG, JPEG, WebP and GIF, up to 4 MB per image, at most 5 images and 16 MB per message.

Language and history

The assistant answers in the language you write in. Conversations are stored on your device only — they are not kept on our servers, and clearing them in the app removes them for good.

Requirements and limits

  • You need to be signed in — the assistant runs through your ProxyTool account
  • Every message costs AI credits
  • Up to 10 messages per minute per device, and 15 per minute per account across all clients
  • Organisation admins can hide the Assistant page or block its use through Device Restrictions
Just importing a proxy string does not need the assistant at all. Quick Add on the Proxies page parses formats like socks5://host:port:user:pass or a curl -x command locally on your machine — no request, no credits. See Adding a Proxy.

What leaves your device

Your message, the configuration summary above and any image you attach are sent to Google Gemini (model gemini-2.5-flash) through ProxyTool's backend — the API key stays on our servers. Passwords inside proxy URLs and host:port:user:pass strings are masked before the request leaves us. Images are forwarded as they are, so avoid screenshots that show credentials. Message content is not stored in our database; only the credit usage of a request is recorded. Details in the privacy policy.

AI Credits & Limits

The assistant in the Windows client, the macOS client, the Android app and the AI Policy Assistant in the web dashboard share one credit balance per account. You find it under Account → Billing → AI Credits.

Included every month

PlanCredits per month
Free20
Trial20
Standard100
Team Premium500

The monthly allowance resets 30 days after the last reset.

What a message costs

Each request reserves 3 credits, plus 8 credits per attached image. The real cost is then calculated from the tokens the model actually used, with a minimum of 1 credit per message — whatever was reserved but not needed is returned to your balance right away. Short questions therefore usually cost a single credit.

Buying more

PackagePrice
500 credits$3.99
1,100 credits$5.99
2,000 credits$9.99
Purchased credits are cleared at the next monthly reset. Buy what you expect to use in the current period rather than stocking up.

Teams

  • Members without their own paid plan spend from the organisation owner's balance
  • An owner can cap how many credits a single member may use per month; once the cap is reached, the assistant asks the member to contact their admin
  • Team root admins can delegate credits to sub-organisations under Account → Billing
  • When the balance is empty, the assistant declines the request instead of answering — nothing is charged and nothing is changed
New chapter

macOS Client

Same account, same rules, same proxies — captured through a macOS Network Extension instead of a Windows kernel driver. Screenshots below are from the live app at 1920×1050.

Getting Started

ProxyTool for macOS routes traffic through a Network Extension (system extension) that macOS loads once you approve it. Every connection the extension sees is then matched against your rules — proxy, chain, direct, or block — without changing Chrome, Safari, or any other app.

Quick Setup (4 Steps)

  • Sign in — the client opens your browser (PKCE). Your password is never typed into ProxyTool
  • Install the system extension — Settings → Engine → Install, then allow it in System Settings when macOS asks. The app must live in /Applications
  • Add a proxy and create a routing rule
  • Start — sidebar Start, or Start Routing on the Dashboard. Traffic follows the rules immediately

Account & Sign-In

The same account covers the web dashboard, Windows, macOS and Android. Sign in at /auth/login. Two-factor authentication finishes in the browser before the client receives a session.

macOS Sign-In PKCE in the system browser. No password is stored in the app.
Device Consent Each Mac uses one licence slot from the same pool as Windows and Android.
Offline grace If the licence check cannot reach the server, the last confirmation stays valid for 72 hours. After that, rules still exist but behave as Direct until the next successful check.
Web Dashboard Policies and restrictions push to Macs the same way they do to Windows. See Web Dashboard.

Dashboard at a Glance

Stat cards Active Connections, Total Traffic, Current Speed, Blocked Leaks, Uptime.
My Proxies / Routing Rules / Chains The same objects as on the dedicated pages, with + Add shortcuts. Rule toggles work from here.
Proxy Health, Top Destinations, Top Apps, Security Events Widgets that fill in as soon as connections use a proxy or leak protection stops traffic.
Live Connections Newest activity at the foot of the dashboard. Connections in the header jumps to Monitoring → Live Connections.
Start / Stop Sidebar Start / Stop, and Start Routing / Stop Routing on the dashboard. Both talk to the same engine.

Customize Your Dashboard

Click Customize, then toggle each stat card and widget. Reset restores the default set. Done leaves edit mode. Unlike Windows, the macOS layout is remembered after a restart.

Navigation

The sidebar uses the same groups as Windows:

  • MAIN — Dashboard, Proxies, Rules, Assistant
  • NETWORK — Chains, DNS, Monitoring
  • SYSTEM — Logs, Settings
macOS only loads the Network Extension from an app in /Applications. Keep ProxyTool there. The first install asks for your approval in System Settings; until that is granted, Start does nothing useful.
JA3 TLS-fingerprint warnings are a Windows Monitoring feature. macOS still inspects TLS Client Hello bytes to recover a hostname when DNS did not; it does not show the Windows “DETECTABLE / BLOCKED” fingerprint cards. Cost analytics do exist under Monitoring.

Adding a Proxy

Open Proxies and click + Add Proxy. Paste a provider string into Name (host:port:user:password, a proxy URL, or a curl -x command) or fill in the fields. Test checks the endpoint before you save; Add Proxy stays disabled until Host and Port are valid.

Server Details

Name Optional label, or a pasteable proxy line that fills Host, Port, protocol and credentials.
Host Address Hostname or IP. Required.
Port 1–65535. Defaults follow the protocol (HTTP 8080, HTTPS 8443, SOCKS 1080).
Protocol HTTP, HTTPS, SOCKS4 or SOCKS5. SOCKS5 carries UDP. HTTPS here means HTTP CONNECT — the usual “HTTPS proxy” from a provider — not TLS to the proxy itself.

Options by Protocol

Options Panel at a Glance
Option HTTP / HTTPS SOCKS4 SOCKS5
Authentication None or Username/Password. NTLM and Kerberos are listed as not implemented on macOS User ID (optional, not a password) None or Username/Password
SOCKS4a Extension N/A Resolve names on the proxy Built-in remote DNS
Use Target Hostname Send the name in CONNECT instead of a resolved IP N/A N/A
Encrypt Connection to Proxy (TLS) TLS to the proxy itself. Leave off for a bought “HTTPS proxy” N/A N/A
Appear as Web Browser / Send User-Agent CONNECT headers some gateways require N/A N/A
Cost per GB / Location Yes — used on Monitoring. Test fills location and country Yes Yes

Advanced Proxy Settings

Expand ADVANCED OPTIONS in Add / Edit Proxy. The subtitle while collapsed is “Credential prompts and authentication URL”.

Add Proxy — Advanced Options expanded: Ask Credentials if Empty, Ask Credentials if Auth Fails Advanced Options — credential prompts when fields are empty or auth fails
OptionDefaultWhat it does
Ask Credentials if EmptyOnPrompt for user name and password when the fields are blank instead of failing the connection
Ask Credentials if Auth FailsOnPrompt again when the proxy rejects the stored credentials
Use Authentication URLOffAuthorise through a web address (Blue Coat and similar) instead of a dialog

Proxy test

Test in the dialog footer runs the checker in place: TCP, protocol handshake, authentication, then a target connection. A success panel shows IPv4 / IPv6 / UDP / Remote DNS badges when the probe can tell. A failure names the stage and, on a credential reject, offers a jump back to the username and password fields.

Test All on the Proxies page runs the same check for every listed server without opening the editor.

Managing Proxies

The list shows protocol badge, address, IPv4/IPv6, remote DNS, location and latency once a test has run. Search filters name, host, port or location. The protocol chips (All / HTTP / HTTPS / SOCKS4 / SOCKS5) narrow the list.

macOS Proxies — five servers, Test All and Add Proxy Proxies — protocol filters, search, Test All and Add Proxy

Row actions

  • Test — reachability without opening the editor
  • Edit — same dialog as Add Proxy
  • Delete — confirms which rules fall back and which chains lose a hop

Select several rows to Test or Delete in bulk. A restriction profile can hide Add Proxy or lock passwords — see Restriction Editor.

Routing Rules

Rules are matched top to bottom — the first matching enabled rule wins. Click + Add Rule. Enable or disable a rule from the list (not inside the dialog), so you see immediately which rule takes over. Drag a row, or use the arrows, to change priority. The fallback rule stays locked at the bottom.

Seeded rules

  • localhost — Direct for loopback and typical local names
  • Default — catch-all, always last. You can change its action (Direct / Proxy / Chain / Block) but not its match fields

Rule setup

FieldFormatExamples
Rule NameLabelBrowsers via Frankfurt
ApplicationsBundle ID, executable name or path; ;-separated; * = every appcom.apple.Safari; com.google.Chrome
Target HostsNames, IPs, CIDR, wildcards. An entry without a wildcard is exact — example.com does not cover www.example.com*.google.com; 10.0.0.0/8
Target PortsPorts, ranges, or *80; 443; 8000-9000
ProtocolTCP, UDP, or both. UDP needs a SOCKS5 hop
ActionProxy, Chain, Direct, Block — one picker, not two steps

Choose… opens a file panel on /Applications. Apple’s own apps are not in that folder — type com.apple.Safari (or ask the Assistant from the notice under the field).

Advanced Routing

OptionWhat it does
Allow IPv6 targetsOff by default. On, IPv6 destinations follow this rule. If the proxy cannot carry IPv6, those connections fail instead of leaking.
Outgoing InterfaceBind the rule to a specific Mac interface (Wi-Fi, Ethernet, …) or any interface.
If That Interface Is DownWhat to do when the chosen interface is missing — shown when a specific interface is selected.

Proxy Chains

A chain is one routing target made of several proxies. Open Chains and click + Add Chain. Unlike Android, macOS has a Chain Active switch: a switched-off chain stays configured but carries no traffic; rules pointing at it fall back to the global default.

Chain Type Comparison
Aspect Chain Redundancy Load Balancing
How it works Every hop in order (multi-hop) First reachable hop; the rest stay in reserve Each connection picks one hop
Windows name Simple Redundancy Load Balancing
UDP Not carried through nested hops Yes, if the chosen hop is SOCKS5 Yes, if the chosen hop is SOCKS5
On failure The whole chain fails Tries the next hop Drops the failed hop from the pool

Type-specific options

OptionApplies toDescription
Connection Timeout (s)AllHow long a hop may take to accept
Recheck Failed Hops (s)Redundancy / Load BalancingBackground re-test of hops that failed
Connect Directly if All Hops FailRedundancy / Load BalancingBypass instead of blocking when the list is exhausted — a kill-switch exception, shown as a warning
Same Proxy for Same ProcessLoad BalancingA process keeps the hop it first got (sticky PID)

Creating a Chain

  1. Chain Name — required, so rules can refer to it
  2. Chain Active — leave on unless you want the chain configured but idle
  3. Chain Type — Chain, Redundancy or Load Balancing. The purple note under the selector explains the chosen type
  4. Available Proxies — click + to add a hop
  5. Chain Order — reorder with the arrows; traffic on a sequential chain flows top to bottom
  6. Add Chain — then pick it as the action on a rule

TLS to the proxy itself can only be the first hop of a chain. Inner hops cannot wrap another TLS session to the next proxy.

DNS & Name Resolution

DNS opens Name Resolution. The status card shows what is actually happening right now — with auto-detect on, that can differ from the switch below. Run Probe asks the running extension to check the local resolver (Start routing first).

macOS Name Resolution — Automatic, Local, counters, detect automatically, upstream resolvers, name list Name Resolution — current mode, resolution switches, upstream resolvers and name list
Detect DNS settings automatically Watches the local resolver and switches to resolution through the proxy when it stops answering.
Resolve host names through the proxy Send lookups through the proxy. With auto-detect on, this only sets the starting point — the card shows a Managed badge.
Upstream Resolvers Queried through the proxy. Semicolon-separated; the first one that answers wins. Default 1.1.1.1; 8.8.8.8.
Query Timeout / Response TTL How long a lookup through the proxy may take, and how long apps may cache the answers we hand out.
DNS Name List Exclude listed names or Include only listed names. Semicolon-separated patterns, e.g. localhost; *.local; %ComputerName%.
Fake-IP Mapping Hands out synthetic addresses (default 198.18.0.0/15 / fc00:7074::/32) so apps that resolve themselves still match hostname rules. Only active while names are resolved through the proxy.
Encrypted DNS Block encrypted DNS discovery answers _dns.resolver.arpa with NXDOMAIN (Apple’s own DoH upgrade path). Block known DoH endpoints turns away Cloudflare, Google, Quad9, AdGuard and similar.

IP Protection

Leak protection lives on the same DNS page, in the Leak Protection card — not under Settings (that is the Android layout). Independent of every switch here: when a rule sends a process through a proxy that cannot carry UDP (HTTP, HTTPS, SOCKS4), that UDP is dropped rather than sent in the clear.

SettingWhat it does
Enable leak protectionMaster switch. Off, none of the rows below apply
Apply to all connectionsExtend the checks to Direct flows, not only proxied ones
Protect IPv6 UDP pathsBlock IPv6 UDP that is not on a safe relay path
Harden browser QUICBlock UDP/443 from browsers so they fall back to TCP+TLS through the proxy
Strict DNS over proxyWhile resolving through the proxy, only allow query types the proxy can carry
Detect connection loopsStop a program that reconnects endlessly after the configured attempts / window

Traffic Monitor

Monitoring has two tabs: Traffic Monitoring (analytics) and Live Connections (the table). Logs are a separate sidebar item under SYSTEM.

Traffic Monitoring Active connections, sent/received, errors, leaks blocked. Traffic by app / proxy / domain / process. Protection overview ring, proxy usage, bandwidth chart, forensics, cost (when Cost per GB is set), protocol insights, security events.
Live Connections TIME, APP, TARGET, PORT, PROTO, RULE, HOST SOURCE, STATE, SENT, RECEIVED, DURATION. Filters: All / Active / Closed / Failed / Blocked. Export CSV, Clear, Follow, Pause.
Logs Engine stream. Severity chips double as filters. Follow tail, copy, clear, font size. Same events the Windows live log shows, as their own page.

Application Settings

Settings is two columns: a searchable section list, then the page. Five entries — Subscription, General, Engine, Profiles, About & Help. Apply Now in the header pushes unapplied configuration to the running extension.

Subscription

Signed-in identity, plan (for example Team Premium), licence state (whether the engine may use proxies), last online check, and Sign out. Sign-out is never restricted. Seats and billing for a team plan belong to the administrator and are not shown on the device — open Manage Account for those.

General

CardSettings
AppearanceTheme: System, Light, Dark
BehaviourLaunch at login (may need approval under System Settings → General → Login Items), Show the menu bar icon, Close to the menu bar, Start the engine on launch
NotificationsMaster switch, then “A proxy failed” and “A proxy asks for credentials”. If macOS is blocking notifications, a notice links to System Settings

Engine

CardSettings
LoggingLog level, Show direct connections, Log UDP packets
LimitsConnect timeout, idle timeout, relay buffer, maximum connections — with Reset
System extensionInstallation state, tunnel state, version. Install / Reinstall / Remove. macOS requires the app in /Applications
DiagnosticsWhat the extension reports about itself; copy / send a support report

Profiles & Migration

Settings → Profiles is a named profile library (Windows-style), not Android’s import/export-only page.

Settings — Profiles library, password encryption, Migrate from Proxifier Profiles — library, encryption modes and Proxifier migration
  • New Profile… / Save Current Setup as Profile — snapshot of proxies, chains, rules, DNS and leak protection
  • Import… / Export Current….ppx files, with encryption matching this Mac, none, or a password of their own
  • Password Encryption — No encryption; This Mac only (Keychain, the counterpart of Windows “Current user account”); Master password (needs a password set first)
Windows DPAPI (“Current user account”) passwords cannot be decrypted on macOS. Re-enter them after import. The same is true of Proxifier passwords that were stored that way.

Migrate from Proxifier

Settings → Profiles → Start Migration… reads a Proxifier .ppx / .xml and shows what it found before anything is changed — including which passwords it can carry over and which have to be typed again. Process names become bundle identifiers where ProxyTool knows the match; edit the rest with Choose… or by typing the bundle ID.

Configuration Assistant

Assistant in the sidebar turns a sentence into a configuration change. Nothing is applied until you click Apply on a card.

macOS Assistant — credits, chat list, Apply card for a Chrome rule Assistant — chat list, credit balance and an Apply card
  • Enter sends, Shift+Enter adds a line, ⌘V attaches a screenshot from the clipboard
  • Paperclip attaches images (same limits as the other clients)
  • Credits are the same balance as Windows, Android and the web policy assistant — see AI Credits & Limits
  • A restriction can hide the page or leave it visible but locked

Getting Started

ProxyTool for Android routes traffic through a local VPN tunnel. Every connection on the phone enters the tunnel; the engine then decides — per app, host, port and protocol — whether it goes through a proxy, a chain, direct, or is blocked. You do not change proxy settings inside Chrome, WhatsApp or anything else.

Get the app from Google Play. Phones without the Play Store can take the signed APK from /download.

Quick Setup (4 Steps)

  • Sign in — the app opens your browser. Your password is never typed into ProxyTool
  • Add a proxy — paste a provider string or fill in host, port and type
  • Create a routing rule — pick the apps (package names) that should use the proxy
  • Start proxifying — grant the VPN permission when Android asks, then traffic follows your rules

Account & Sign-In

The same account covers the web dashboard, Windows, macOS and the Android app. Sign in at /auth/login. Two-factor authentication (TOTP or email OTP) is completed in the browser before the app receives a session.

Android Sign-In Uses the same PKCE browser flow as the desktop client. The app never stores your password.
Device Consent Each phone registers as a device on your account and uses one licence slot, the same pool as Windows and macOS installs.
Offline grace If the licence check cannot reach the server, the app keeps working for 72 hours. After that, premium features pause until the next successful check.
Web Dashboard Administrators push policies and restrictions to phones the same way they do to desktops. See Web Dashboard.

Dashboard at a Glance

Tunnel control Start proxifying / Stop proxifying. States: Not proxifying, Starting…, Proxifying, Reconnecting, Couldn't start. While running you also see throughput, blocked connections and leaks prevented.
Stat cards Active connections, Proxies (reachable / total), Rules (enabled / total), Transfer (sent / received), Uptime.
My proxies Configured servers with type badge, address and latency. The + opens Add proxy.
Bandwidth Last 60 seconds of upload and download. The chart fills in once the tunnel is up.
Routing rules / Chains / Live logs The same panels as on desktop, stacked on a phone. Live connections can be frozen from the widget.

Customize Your Dashboard

Tap the tune icon under the page title to open Customize dashboard. Toggle each stat card and widget, reorder with the arrows, then Done. Reset all restores the default layout.

Navigation

On a phone the floating bar shows Dashboard, Proxies, Rules, Assistant, Logs and Settings. More (the three dots) opens Chains, DNS and Connections. On a tablet you get a sidebar with the same MAIN / NETWORK / SYSTEM groups as the desktop client.

VPN permission

The first Start proxifying asks Android for a VPN. ProxyTool uses that VPN only as a capture interface — it does not send your traffic to a ProxyTool server. Another VPN app cannot run at the same time. Always-on VPN and lockdown (block connections without VPN) are set in Android Settings → VPN, not in the app; Settings → Startup & Tunnel shows the current state and links there.

Android 13+ also asks for notifications. You can decline; the tunnel still starts, but you lose the shade notification and its Stop button.
TLS fingerprint detection exists only on Windows. Cost analytics exist on Windows and macOS. On Android you can still store Cost per GB on a proxy; there is no monitoring UI for it yet.

Adding a Proxy

Open Proxies and tap + Add proxy. Paste a provider string into Proxy name or quick add, or fill in the fields. Supported paste formats include socks5://user:pass@host:port, host:port:user:pass and a curl -x command.

Server Details

Proxy name or quick add Display name, or a pasteable proxy string / curl command that fills the other fields.
Host address Hostname or IP of the proxy server.
Port Port number (1–65535). 8080
Proxy type HTTP, HTTPS, SOCKS4 or SOCKS5. SOCKS5 is marked Can carry UDP.

Options by Protocol

Options Panel at a Glance
Option HTTP / HTTPS SOCKS4 SOCKS5
Requires authentication Username + Password + Method Replaced by User ID Username + Password
Authentication method None, Basic, NTLM, Negotiate N/A Auto-negotiated
SOCKS4a extension N/A Remote DNS on the proxy N/A (built-in)
Send User-Agent CONNECT header (HTTP/HTTPS only) N/A N/A
Cost per GB Yes — stored on the proxy Yes Yes
NTLM and Negotiate (Kerberos) need a Windows session. On Android they show as unavailable — use Basic, or a SOCKS5 login. There is no “Use current Windows login” switch.

SOCKS4a Extension

Standard SOCKS4 resolves the hostname on the phone first. With SOCKS4a extension on, the hostname is sent to the proxy so local DNS never sees it — the same remote-DNS behaviour SOCKS5 already has.

Advanced Proxy Settings

Expand Advanced options in the Add proxy sheet. The same keys exist on desktop.

OptionDefaultWhat it does
Ask for credentials if emptyOnShows a login sheet at connect time when no password is stored
Ask again if authentication failsOnRe-prompts after HTTP 407 or a SOCKS reject
Use authentication URLOffEnterprise web-auth portals (Blue Coat and similar)
Use target hostnameOffSends the destination name to the proxy instead of a locally resolved IP

Proxy checker

Before you save, open Proxy checker, set a target (default google.com) and tap Check. The steps are DNS resolution, TCP connection, Protocol handshake and Tunnel to target. HTTPS proxies also validate the proxy’s TLS certificate.

Runtime login

When a proxy needs a password, a sheet titled Proxy authentication appears. Save to profile stores the password encrypted on the device; otherwise it lasts for this session only. Ignore this session skips that proxy until you restart.

Managing Proxies

The Proxies page lists every server with reachability, protocol badge and latency. The subtitle reads e.g. 1 proxies · 1 reachable. Search filters by name, host or type.

Android Proxies — evomi.com SOCKS5, 1 reachable, Test all and Add proxy Proxies — reachable SOCKS5 server with Test all and Add proxy

Row actions

  • Test proxy / Test all — reachability check without opening the editor
  • Edit / Duplicate
  • Set as default route — points the locked Default catch-all rule at this proxy (or back to Direct)
  • Enable / Disable
  • Enter credentials / Forget session login
  • Delete — shows which rules fall back to Direct and which chains lose a hop

Badges

Default, Disabled, Session login, Login needed, {method} unavailable (NTLM/Negotiate on Android).

A restriction profile can hide Add proxy or make the form read-only. See Restriction Editor.

Routing Rules

Rules are matched top to bottom — the first matching rule wins. Tap + New rule to open the editor. New rules start disabled so nothing routes until you turn them on. Long-press a card to drag it into position, or use the up/down arrows.

Seeded rules

  • localhost — Direct for loopback and private ranges
  • Default — catch-all, locked: you cannot delete it, disable it, or edit its targets. Change where leftover traffic goes with Set as default route on a proxy, or by editing the action

ProxyTool itself is never listed in the app picker; its own traffic (licence, heartbeat) always goes direct so the tunnel cannot lock itself out.

Rule setup

FieldFormatExamples
NameLabelChrome through EU
ApplicationsPackages, ;-separated, or *com.android.chrome; org.mozilla.*
Target hostsNames, IPs, CIDR, wildcards*.example.com; 10.0.0.0/8
Target portsPorts or ranges443; 8000-9000
ProtocolTCP / UDP / TCP + UDPUDP needs SOCKS5
ActionProxy, Chain, Direct, Block

Choose installed apps opens a picker split into Apps and System and background packages. Turn on Show every package if the app you want is hidden.

Advanced Routing

OptionWhat it does
Allow IPv6Let this rule match IPv6 destinations. Combined with Suppress AAAA answers on the DNS page.
Interface / TransportLimit the rule to Wi-Fi, Mobile data, Ethernet, VPN or Bluetooth — or any interface.
If the interface is downFall back automatically, connect directly, or block.

Chips on a rule card call out Catch-all, IPv6, UDP not supported (sequential chain + UDP), {n} hops and Route missing (the proxy or chain was deleted).

Proxy Chains

A chain is a single routing target made of two or more proxies. Open More → Chains and tap + New chain. You need at least two proxies first. Chains have no on/off switch of their own — assign one to a rule.

Chain Type Comparison
Aspect Sequential Failover Load balancing
How it works Every hop in order (multi-hop) First reachable hop; the rest stay in reserve Spread across enabled hops
Desktop name Simple Redundancy Load Balancing
UDP Not carried — nested UDP ASSOCIATE is not possible. Matching UDP falls through Yes, if the chosen hop is SOCKS5 Yes, if the chosen hop is SOCKS5
On failure The whole chain fails Tries the next hop Drops the failed hop from the pool

Type-specific options

OptionApplies toDescription
Connection timeoutFailoverHow long to wait before declaring a hop failed
Recheck failed hopsFailoverBackground re-test of hops that failed
Connect directly if all hops failFailoverBypass instead of blocking when the list is exhausted
Keep an app on one hopLoad balancingSticky sessions — one hop per app instead of per connection
HTTP/HTTPS may only be the last hop of a Sequential chain. Earlier hops must be SOCKS4 or SOCKS5.

Creating a Chain

  1. Name — e.g. “EU double hop”
  2. Chain type — Sequential, Failover or Load balancing
  3. Hops — add at least two proxies, drag to reorder, enable or disable a hop without removing it
  4. Options — timeout / recheck / sticky session as above
  5. Create chain — then pick it as the action on a rule

Runtime badges: UDP, TCP only, Used by {n} rules, {n} failed, Proxy deleted. Reset failure status clears a hop that Failover marked down.

DNS & Name Resolution

More → DNS opens Name Resolution. The status card shows Detection (Automatic / Manual), Resolution (Proxy / Local) and the name-list mode. Changes apply to a running tunnel immediately — tap Apply Settings.

Detect DNS settings automatically Watches the network and switches mode when local DNS is unavailable. Locks the manual “resolve via proxy” switch while on.
Resolve hostnames through proxy Send lookups through a SOCKS5 (or a failover / load-balancing chain of SOCKS5 hops). Sequential chains cannot carry DNS.
Strict DNS over proxy Fail closed when a lookup cannot go through the proxy. The same switch lives under Leak protection — it is one setting.
Name list Do NOT resolve the following (exclude) or Resolve ONLY the following (include). Semicolon-separated patterns, e.g. *.local;*.lan.
Resolvers Queried on this device (empty = system resolver) and Queried through the proxy (defaults 1.1.1.1 and 8.8.8.8).
Match rules by hostname (FakeIP) Hands out addresses from 198.18.0.0/15 so a TCP flow can still match a hostname rule. Off, *.example.com never matches.
Suppress AAAA answers Empty IPv6 answers unless the matching rule opted into IPv6.
Cache TTL How long positive answers are kept. 0 disables the cache.

IP Protection

Leak protection lives in Settings → Leak protection (and a subset is pushed from a policy). The master switch turns the group on; Detect connection loops works even when the master is off.

SettingDefaultWhat it does
Leak protectionOnMaster switch for the rows below
Apply to every connectionOffProtect Direct flows too, not only proxied ones
Block unsafe UDP fallbackOnDrop UDP that cannot be tunnelled instead of sending it in the clear
Protect IPv6 UDP pathsOnSame protection for IPv6 destinations
Harden browser QUICOnReject QUIC on port 443 so browsers fall back to TCP through the proxy
Strict DNS over proxyOnShared with the DNS page
Block an app's own proxyOffRefuse connections an app makes to a proxy it configured itself
Detect connection loopsOnBlocks a proxied flow whose destination is one of your own proxies

There is no “name-resolution loop” switch. The engine always resolves proxy hostnames outside the tunnel, so that loop cannot happen.

Traffic Monitor

More → Connections is the live monitor — one page, no Analytics tab. Freeze, resume, clear history, open Statistics, search, and filter by state, route, protocol or source.

Android Connections — active connections, sent, received, bandwidth Connections — live table with app, target, rule and traffic
Columns APP, TARGET, PROTO, RULE / ROUTE, STATE, sent, received, RATE, TIME
States Resolving, Connecting, Handshaking, Active, Closed, Failed, Blocked
Source filter Apps only, System, or ProxyTool itself (always direct)

Logs (bottom bar) is the engine log: level and source filters, auto-follow, copy, share, clear, and font size. That is the phone equivalent of the desktop live log stream.

Application Settings

Settings is searchable. A lock banner Managed by your organisation means a restriction profile owns that control.

Profile files

Import and export .ppx configurations from Settings → Profiles. See Profiles & Migration for encryption modes and Proxifier import details.

Appearance

Theme — System, Light, Dark. Language — System default, English, Deutsch. The screen redraws immediately.

Startup & Tunnel

SettingNotes
Start with the deviceRead-only. Android owns this as always-on VPN. Open VPN settings jumps there. Lockdown (“block connections without VPN”) is also a system setting.
Ongoing notificationConnections and throughput, or only that proxifying is running
Clamp the TCP MSSAvoids blackholes on carriers that drop ICMP
When a connection cannot be attributed to an appApply the default rule, send it direct, or block it
Tunnel MTU1280–9000, default 1500
TimeoutsConnection (1–120s), idle (10–3600s), UDP session (5–600s)

Logging & Diagnostics

Log level (Errors only → Trace), Show direct connections in the log, UDP per-packet logging, retention 100–100000 entries. There is no traffic-dump recorder on Android; a policy may still carry the desktop switch and the app ignores it.

Reset, Support, Account

Restore defaults resets settings and DNS only — proxies, chains and rules stay. Send log to support uploads the stored log and returns a reference number. Sign out is never restricted.

Profiles & Migration

Android has no named profile library. You import and export .ppx files from Settings → Profiles. A policy push from the dashboard is a separate path — see Policy Profiles.

  • Export… — pick a name and an encryption mode, then the system document picker
  • Import…Add to the current configuration or Replace the current configuration. Optionally apply settings from the file. Imported rules arrive disabled
  • Encryption — None, Basic, Windows account (DPAPI), Master password (GCM), Master password (compatible)
DPAPI (“Windows account”) passwords cannot be decrypted on Android. Re-enter them after import. The same is true of Proxifier passwords.

Migrate from Proxifier

Settings → Profiles → Choose Proxifier profile… merges proxies, chains and rules from a Proxifier .ppx / .xml. Process names are mapped to Android packages where ProxyTool knows the match (Chrome, Firefox, Signal, …). Unknown names stay as they were — edit those rules and pick packages with Choose installed apps.

Configuration Assistant

The Assistant is on the bottom bar. Describe what should run through a proxy; it proposes proxies, rules, chains and settings. Nothing is applied until you tap Apply on a card. Rules created this way are enabled immediately (unlike a manual New rule).

Android Assistant — credits, Route an app, Parse a proxy string, chat input Assistant — quick prompts and credit balance
  • Quick prompts: Route an app, Parse a proxy string, Read a screenshot
  • Up to 5 images, 4 MB each (PNG, JPEG, WebP, GIF)
  • Credits are the same balance as desktop and the web policy assistant — see AI Credits & Limits
  • hideAssistant removes the page; canUseAi leaves it visible but locked
New chapter

Web Dashboard

Administration for every client type — Windows, macOS, Android, and fleet devices — from one portal. Policies, restrictions, users, and billing live here.

Web Dashboard Overview

The web dashboard at /dashboard is where administrators manage organizations, deploy proxy configurations to managed devices, and control what end users can do in the Windows, macOS and Android clients. It is separate from any client's own Dashboard page — this section documents the web admin portal.

Sidebar Navigation

SectionPagesAvailability
OverviewDashboard, Proxies, Download Client, Network OverviewNetwork Overview requires Fleet access
ManagementFleet, Users, Groups, Policies, Restrictions, Permissions & RolesPlan-dependent (see below)
AccountBilling, Referral, SettingsAlways
SupportHelp & SupportAlways

Plan Features

FeatureStandard / TrialTeam Premium
FleetYesYes
GroupsYesYes
PoliciesYesYes
AutomationsYesYes
Users & RolesNoYes
Device RestrictionsNoYes
Permissions & RolesNoYes
Entitlements / Credit PoolNoYes

Deployment Flow

Managed configurations reach devices through groups — not by assigning directly to individual devices:

  1. Create a Policy — define proxies, chains, rules, DNS, and app settings in the Policy Editor
  2. Create a Restriction (Team Premium) — optionally limit what users can change on Windows, macOS and Android
  3. Create a Device Group — add the target devices as members
  4. Assign Policy & Restriction to the group — from the Policy or Restriction editor (Summary / Assignments tab)
  5. Push — configurations are queued for every device in the group and collected with the device's next heartbeat
  6. Verify in Fleet — check device status, applied policy version, and active configuration
One policy + one restriction per group. Each device group can have at most one assigned policy and one assigned restriction. Assigning a new one to a group that already has one triggers an override confirmation dialog.
Policies vs Restrictions
  • Policy = what configuration devices use (proxies, rules, chains, DNS, app settings)
  • Restriction = what users are allowed to see and change on each client. Shared keys reach every device; desktop, Windows-only, macOS-only and Android-only keys are delivered only to those platforms

Device Groups

Device groups organize managed devices for bulk policy and restriction deployment. Navigate to Management → Groups in the web dashboard.

Creating a Group

NameDisplay name for the group (e.g. "Engineering Devices")
DescriptionOptional notes about the group's purpose
TypeAlways Device Group — groups contain managed fleet devices

Managing Members

  • + Add Devices — select one or more fleet devices from a multi-select panel and add them to the group
  • Remove — remove individual devices from the expanded group view
  • Device count and member previews are shown in the collapsed group row

Assigned Policy & Restriction

When a group has an assigned policy or restriction, they are shown in the group detail panel. To change assignments, use the Policy Editor (Summary tab) or Restriction Editor (Assignments tab).

Assign policies and restrictions from the Policy/Restriction pages, not from the Groups page.

Policy Profiles

Policy profiles are managed configurations (proxies, chains, rules, DNS, app settings) that can be pushed to device groups. Navigate to Management → Policies.

Policy List

+ Create PolicyOpens the Policy Editor to build a new profile from scratch or import a .ppx file
AI AssistantBuilds and edits policy configuration from a plain-language description — see AI Policy Assistant
EditOpen the Policy Editor for an existing profile
Push & ReleaseDeploy the current policy version to all devices in assigned groups; each one collects it with its next heartbeat
Download .ppxExport the policy as a Proxifier/ProxyTool profile file
Delete PolicyPermanently remove the policy profile

Apply Mode

AdditiveMerges the pushed policy with any existing local configuration on the device. Local settings not covered by the policy are preserved.
OverrideReplaces the device's entire configuration with the policy. Local settings are overwritten.

On Android, Additive merges proxies, chains and rules into the current file and then applies only the androidSettings keys you marked as managed. Override replaces the file, then applies those settings. Windows devices receive the Windows settings block instead.

Group Assignment

From the expanded policy row or the Policy Editor Summary tab:

  • Select a group from the dropdown and click Assign to Group
  • If the group already has a different policy, a confirmation dialog asks whether to override
  • Assigned groups show device counts and online status; outdated devices (running an older policy version) are highlighted
  • Unassign removes the policy from a group without deleting the policy itself

Policy Editor

The Policy Editor has six tabs. Use Import .ppx to load an existing Proxifier or ProxyTool profile, or build from scratch. Save with Save or deploy immediately with Save & Push.

Tab: Proxies

Define proxy servers included in this policy. Toolbar: + Add Proxy, Expand All, Collapse All.

FieldDescription
Proxy NameDisplay label used in rules and chains
Host Address / PortProxy server connection details
Proxy TypeHTTP, HTTPS, SOCKS4, or SOCKS5
Requires AuthenticationEnable username/password auth (HTTP/HTTPS/SOCKS5)
MethodBasic, NTLM, or Negotiate (Kerberos) — HTTP/HTTPS only
Use Windows Login (SSPI)Use current Windows credentials for NTLM/Negotiate
Username / PasswordInline credentials when not using SSPI
Send User-Agent in CONNECTInclude a custom User-Agent header in HTTP CONNECT
User-AgentCustom User-Agent string value
User Identification (SOCKS4)SOCKS4 user ID field
SOCKS4a ExtensionLet proxy resolve hostnames remotely (SOCKS4a)
Cost per GB ($)Rate used for cost tracking in the desktop monitor
Ask credentials if emptyPrompt user when credentials are missing
Ask if auth failsRe-prompt on authentication failure
Use Target HostnameSend hostname instead of IP to proxy
Authentication URLWeb-based auth URL for enterprise proxies (Blue Coat, etc.)

Tab: Chains

SettingDescription
Chain NameLabel referenced by routing rules
Simple (Sequential)Traffic passes through all proxies in order (multi-hop). HTTP/HTTPS must be the last hop.
Redundancy (Failover)Try proxies in order; switch on failure. Options: Timeout (sec), Recheck (sec), Direct if all fail.
Load BalancingRandom proxy per connection. Option: Same proxy per PID (session stickiness).
Hop Sequence / Failover Order / Pool MembersOrdered list of proxies in the chain — add via proxy buttons

Tab: Rules

Rules are evaluated top to bottom — rule #1 has highest priority. Built-in rules: localhost (Direct) and Default (Direct).

FieldDescription
Rule nameDescriptive label
Enable toggleActivate or deactivate without deleting
App (process / package)Desktop uses process names (firefox.exe; chrome.exe). Android uses package names (org.mozilla.firefox; com.android.chrome). A mixed fleet can carry both in the same field — each client matches the form it understands.
Hosts (targets)Target hostnames or IP patterns
Ports (targets)Target port numbers or ranges
ProtocolTCP + UDP, TCP only, or UDP only (UDP requires SOCKS5)
Action: DirectBypass proxy — connect directly
Action: ProxyRoute via a specific proxy. Options: Via Proxy, IPv6 through proxy, Interface (Auto/Specific)
Action: ChainRoute via a proxy chain. Options: Via Chain, IPv6 through proxy, Interface
Action: BlockDrop matching connections

Tab: DNS & Security

Auto-detect DNS settingsUse system DNS configuration as baseline
Resolve hostnames through proxyRemote DNS resolution via proxy (prevents DNS leaks)
Name List ModeDo NOT resolve listed names locally, or Resolve ONLY listed names through proxy
Exclude/Include Name ListWildcard patterns: %ComputerName%, *.local, etc.
Enable all protectionMaster toggle for IP leak protection
Block unsafe UDP fallbackDrop UDP when proxy cannot relay it
Protect IPv6 UDP pathsBlock IPv6 UDP leaks
Strict DNS over proxyForce all DNS through proxy tunnel

Tab: App Settings

Each setting has a Manage checkbox (include in policy) and a value control. Unmanaged settings stay under user control on the device. The tab is split by platform: a device receives only its own group. An empty group leaves the device on its own defaults — there is no inheritance from another platform. Windows and Linux share the first group (same Qt client). A Mac never receives Windows, iOS or Android keys; an iPhone or iPad never receives desktop or Android keys; Android never receives desktop or Apple keys.

Windows + Linux

CategorySettings
SystemIcon in System Tray, Minimize to System Tray, Start with Windows
NotificationsDesktop Notifications
MonitoringShow Traffic on Tray Icon, Show Direct Logs & Connections
SafetyInfinite Connection Loop Detection, Infinite Name Resolution Loop Detection
DiagnosticsDebug Mode (logs to %LOCALAPPDATA%/ProxyTool/Logs/)
Profile & UpdatesUpdate Profile on Start, Keep Credentials on Update, Password Encryption (Disabled / Basic / DPAPI / Master Password)

macOS

Stored as macosSettings on the policy. Keys match Settings on the Mac. A Mac uses only this group. With nothing managed here it keeps its own defaults — it never inherits the Windows + Linux group.

CategorySettings
AppearanceTheme (Follow system / Light / Dark)
Startup & menu barLaunch at login, Show the menu bar icon, Close to the menu bar, Start the engine on launch
NotificationsMaster switch, report a failed proxy, report a credential prompt
LoggingLog level, show direct connections, log UDP packets
LimitsConnect timeout, idle timeout, relay buffer, maximum connections
Updates & diagnosticsCheck for updates automatically, update channel, send diagnostics

iOS + iPadOS

Stored as iosSettings on the policy. iPhone and iPad share this group because they are the same app. Keys match Settings on the device. With nothing managed here the device keeps its own defaults — it never inherits Windows + Linux, macOS or Android keys.

CategorySettings
AppearanceTheme (System / Light / Dark), Language (System / English / Deutsch)
BehaviourStart the engine on open, keep routing on, haptic feedback, confirm before delete
VPN profileConnect VPN automatically (on-demand), block until the tunnel is up, exclude local networks
NotificationsMaster switch, report a blocked leak, report a failed proxy, report a tunnel restart
LoggingLog level, show direct connections, log UDP packets, traffic dump
LimitsConnect timeout, idle timeout, relay buffer, maximum connections, tunnel MTU

Android

Stored as androidSettings on the policy. Keys match the field names on the phone. An Android device uses only this group — it never inherits Windows + Linux, macOS or iOS keys.

CategorySettings
AppearanceTheme (System / Light / Dark), Language (System default / English / Deutsch)
Notification & tunnelOngoing notification content, Clamp the TCP MSS, unknown-app policy, Tunnel MTU, connection / idle / UDP session timeouts
Leak protectionMaster switch, apply to every connection, block unsafe UDP fallback, protect IPv6 UDP, harden browser QUIC, strict DNS over proxy, block an app's own proxy, detect connection loops
LoggingLog level, show direct connections, UDP per-packet logging, retention. Traffic dump is accepted and ignored — the Android engine does not record payloads
DNSResolve via proxy, auto-detect, name-list mode and list, local / proxy resolvers, FakeIP, suppress AAAA, cache TTL. These win over the same four fields in the shared .ppx DNS block
There is no “start with the device” key for Android. Always-on VPN is an Android system setting; an app cannot set it for itself. Push it through a device-owner MDM if you need it. See Android Application Settings.

Tab: Summary

Shows policy statistics (proxy, chain, rule counts) and the Group Assignments section — assign or unassign groups directly from the editor before pushing.

AI Policy Assistant

The dashboard has its own assistant for building policies. Open Management → Policies and click AI Assistant — a panel slides in from the side of the policy list.

What it can do

Create a policyDescribe the setup in a sentence and get a complete policy — proxies, chains, routing rules and DNS settings — proposed as one action
Extend a policyAdd a proxy, a rule or a chain to a policy that already exists
Push a policyRe-sync a policy to the device groups it is assigned to

As in the desktop client, each proposal carries an Apply button and nothing reaches a device before you press it. After applying, the policy list reloads so you can open the result in the Policy Editor and adjust it by hand.

Context and limits

  • The assistant sees your existing policies — their names, proxies and rules. Fleet devices, telemetry and screenshots are not part of the request
  • Up to 8,192 characters per message, with the last 16 messages of the conversation as context
  • Up to 15 requests per minute per account
  • Image attachments are available in the Windows, macOS and Android assistants, not in this dashboard panel
  • Conversations are not stored on the server — closing the panel or reloading the page clears them
  • Messages are charged against the same AI credit balance as the Windows, macOS and Android assistants

Device Restrictions

Device restrictions control what end users can see and do in the Windows, macOS and Android clients. Available on Team Premium plans. Navigate to Management → Restrictions.

Restriction List

  • + New Restriction Profile — create with name and description
  • Each profile shows active restriction count and assigned group count
  • Edit opens the Restriction Editor
  • Delete removes the profile (also unassigns from groups)

Templates

Lock Policy (Full)Preset that disables proxy/rule/chain editing, locks DNS/leak protection, and locks most profile operations — maximum lockdown
Reset to DefaultRestore all toggles to permissive defaults (everything allowed, nothing hidden)

Save & Apply

Save & Apply stores the restriction profile and reports how many devices it covers. Every device in the assigned groups applies it with its next heartbeat, which it sends once a minute. There is no separate push step: each heartbeat carries the restrictions currently in force, so a device cannot stay out of sync.

Hide vs Allow vs Lock:
Hide (UI Visibility) — removes a page or section from the client's navigation entirely.
Allow (Permissions) — when OFF, the user cannot perform that action (e.g. add a proxy).
Lock (Permissions) — when ON, the user cannot change that setting even if they can see it.
Each key is Shared (all three clients), Desktop (Windows and macOS), Windows only, macOS only, or Android only. A phone is never sent a tray-icon lock; a Mac is never sent a DPAPI lock; a desktop is never sent a tunnel-MTU lock.

Restriction Editor

Three tabs: UI Visibility, Permissions & Locks, and Assignments. Inside each tab the editor groups keys as Shared, Desktop, Windows only, macOS only and Android only, with a badge on every row.

Tab: UI Visibility

Hiding a page removes it from the client's navigation and blocks its route, so a deep link cannot reach it either.

Shared — all three clients

ToggleEffect when enabled (hidden)
Hide DashboardDashboard page removed
Hide ProxiesProxies page removed
Hide RulesRules page removed
Hide AI AssistantAssistant page removed
Hide ChainsChains page removed
Hide DNSDNS / Name Resolution page removed
Hide ConnectionsConnections page removed
Hide LogsLogs page removed
Hide SettingsWhole Settings page removed
Hide Settings — ProfilesProfiles section inside Settings hidden on all three clients

Windows only

ToggleEffect when enabled (hidden)
Hide Analytics tabAnalytics sub-tab on the desktop Connections / Monitoring page (Windows and macOS)
Hide Connections tabConnections sub-tab on the desktop Connections / Monitoring page
Hide Settings — GeneralThe desktop “General” settings item. On macOS this also hides Engine. Android has no General page
Hide Settings — About & HelpDesktop About & Help item. To drop only Updates or Help on a Mac, use the macOS keys below
Hide Settings — AI AssistantWindows-only settings item. macOS hides the Assistant page with “Hide AI Assistant”

macOS only

ToggleEffect when enabled (hidden)
Hide Settings — EngineLogging, limits, system extension and diagnostics — without hiding General
Hide Settings — UpdatesUpdate card on About & Help; version line and support links stay. Required updates still arrive
Hide Settings — Help & SupportDocumentation and support links on About & Help
Hide the system extension cardInstall / Reinstall / Remove. Status notices stay
Hide DiagnosticsDiagnostics report and support upload on Engine
Hide “Migrate from Proxifier”Proxifier import card on Profiles. Windows still uses its own migration UI

Android only

ToggleEffect when enabled (hidden)
Hide Settings — AppearanceTheme and language
Hide Settings — Startup & TunnelAlways-on status, notification, MTU, timeouts
Hide Settings — Leak protectionThe leak-protection section
Hide Settings — Logging & DiagnosticsLog level, direct/UDP logging, retention
Hide Settings — ResetRestore defaults. Worth setting on a managed phone so a user cannot undo a locked value until the next heartbeat

Tab: Permissions & Locks

Proxies

ToggleTypeWhen restricted
Allow Add ProxyAllowUser cannot add new proxy servers
Allow Edit ProxyAllowUser cannot modify existing proxy settings
Allow Delete ProxyAllowUser cannot remove proxy servers
Lock Proxy Authentication CredentialsLockUsername/password fields are read-only

Rules

ToggleTypeWhen restricted
Allow Add RuleAllowUser cannot create new routing rules
Allow Edit RuleAllowUser cannot modify existing rules
Allow Delete RuleAllowUser cannot remove rules
Allow Activate RuleAllowUser cannot enable disabled rules
Allow Deactivate RuleAllowUser cannot disable active rules

Chains

ToggleTypeWhen restricted
Allow Add ChainAllowUser cannot create new proxy chains
Allow Edit ChainAllowUser cannot modify existing chains
Allow Delete ChainAllowUser cannot remove chains

AI Assistant

Allow Using AIWhen OFF, the user can still open the page but cannot send messages to the Configuration Assistant

DNS & Network Protection

Lock DNS ConfigurationUser cannot modify DNS server settings pushed by policy
Lock Leak ProtectionUser cannot disable DNS/WebRTC leak protection toggles

Profiles

ToggleScopeWhen restricted
Allow Import ProfilesSharedUser cannot import a .ppx file
Allow Export ProfilesSharedUser cannot export a .ppx file
Lock Password EncryptionSharedExport encryption choice is locked
Allow Load / Save / Create / Delete ProfilesDesktopProfile library on Windows and macOS. Android has no library — it only imports and exports files

macOS only — actions

ToggleWhen restricted
Allow Managing the System ExtensionUser cannot install, reinstall or remove the network extension
Allow Running DiagnosticsUser cannot produce the local diagnostics report
Allow Sending Logs to SupportUser cannot upload engine, system and crash logs
Allow Checking for UpdatesUser cannot run the update check by hand. Required updates still arrive
Allow Migrating from ProxifierUser cannot start a Proxifier import

Settings & System — Windows only

ToggleWhen locked
Lock Auto-UpdateUser cannot disable the desktop updater (Windows and macOS)
Lock Start with Windows / Launch at loginUser cannot change launch-at-sign-in. Android uses always-on VPN instead
Lock System Tray / Menu bar iconUser cannot hide/show the tray or menu bar icon
Lock Minimize to Tray / Close to the menu barUser cannot change close-to-tray / close-to-menu-bar behaviour
Lock Show Traffic on TrayWindows only — live traffic on the tray icon. macOS has no equivalent
Lock Name Resolution Loop DetectionWindows only. On macOS, lock Connection Loop Detection instead

Settings & System — macOS only

ToggleWhen locked
Lock AppearanceTheme (system / light / dark). Android has its own Appearance lock, which also covers language
Lock Start the Engine on LaunchUser cannot change whether the extension comes up as soon as the app starts
Lock NotificationsMaster switch and the two reports (failed proxy, credential prompt)
Lock Log LevelHow much detail the engine records
Lock Engine LimitsTimeouts, relay buffer, connection ceiling, and the Reset button
Lock Update ChannelStable vs beta. Independent of the auto-update lock
Lock Send DiagnosticsBackground throughput and leak telemetry to the organisation
Lock the System ExtensionState stays visible; install / reinstall / remove are refused. Milder than hiding the card

Settings & System — Android only

ToggleWhen locked
Lock AppearanceTheme and language
Lock Startup & TunnelThe whole section. Implies the two locks below
Lock Ongoing NotificationWhat the shade notification shows while proxifying
Lock Tunnel TuningMSS clamping, unknown-app policy, MTU, the three timeouts
Lock Logging & DiagnosticsThe whole logging section. Implies direct-connection, UDP and traffic-dump locks
Lock All General Settings (retired)Old umbrella for Appearance + Tunnel + Logging. Still honoured if a stored profile already has it; not offered for new profiles. Turn it off and use the section locks

Monitoring & Diagnostics — shared

ToggleWhen locked
Lock Show Direct Connections in LogsUser cannot toggle direct-routed traffic in logs
Lock Connection Loop DetectionUser cannot disable loop detection
Lock UDP Packet LoggingUser cannot enable per-datagram logging
Lock Traffic DumpDesktop dump is blocked. Android accepts the key and records nothing

Tab: Assignments

  • Assigned Groups — lists groups receiving this restriction; click Remove to unassign
  • Select a group to assign… dropdown + Assign Group button
  • One restriction per group — override confirmation if group already has a different restriction
  • All devices in assigned groups receive the restriction automatically on push

Fleet Management

Monitor all enrolled managed devices. Navigate to Management → Fleet.

Fleet Dashboard

KPI CardsTotal, Online, Offline, Pending, Groups, Policies, Commands (24h)
SearchFilter devices by name or identifier
Status FiltersAll, Online, Offline, Pending

Device Table Columns

ColumnDescription
DeviceDevice name and identifier
PlatformOperating system
StatusONLINE, OFFLINE, PENDING_ENROLLMENT, or ERROR
GroupsAssigned device groups
PolicyCurrently applied policy name and version
RestrictionsApplied restriction profile
Last SeenLast heartbeat timestamp

Device Detail Page

Click a device row to open its detail view:

  • Device Information — platform, OS version, app version, enrollment date, last heartbeat
  • Applied Policy — server policy version vs device-reported version; "Update pending" when outdated
  • Current Configuration — active profile, proxy list, chains from device heartbeat
  • Groups & Tags — group membership and custom tags
  • Command History — remote commands with status (PENDING, DELIVERED, EXECUTING, COMPLETED, FAILED, EXPIRED)
Fleet devices vs License slots: Fleet shows managed devices enrolled in your organization (Windows, macOS and Android). The Devices page under Account shows personal license activations — each desktop install and each phone uses one slot. These are separate concepts.

Users & Roles

Manage organization members and invitations. Available on Team Premium. Navigate to Management → Users.

Tabs

MembersView all organization members, their roles, and pending invitations
Add UserCreate a new account and add directly to the organization (no email invite)
InviteSend email invitation with assigned role
ImportBulk invite users from CSV with Invite All

Member Actions

  • Change role — assign a different built-in or custom role
  • Reset password — force password reset for the member
  • Ban / Unban — suspend or restore account access
  • Remove from organization — revoke membership

Built-in Roles

Owner, Admin, Operator, Viewer, Device Manager, Policy Manager, Help Desk — plus custom roles created in Permissions & Roles.

Permissions & Roles

Fine-grained access control for dashboard users. Navigate to Management → Permissions & Roles (Team Premium).

Tabs

RolesView built-in roles and create custom roles with specific permission sets
Role DelegationConfigure which roles sub-organization admins may assign (root admin only)
OverviewMatrix view of members × permissions for a selected category

Permission Categories

CategoryExamples
ProxiesView, create, edit marketplace proxies
ChainsManage proxy chains
DevicesView fleet, wipe devices, remote commands
GroupsCreate, edit, delete device groups
PoliciesCreate, edit, deploy (policy:deploy)
Config OverridesTemporary JSON config overrides
Users & RolesInvite, ban, assign roles
LicensesManage license allocations
AI CreditsManage organization credit pool
Device RestrictionsCreate, edit, assign restrictions
OrganizationOrg settings, billing visibility
AutomationsAutomation rule management

Custom Roles

Click Create Custom Role, set name, description, scope (root or sub-org), and pick permissions from the catalog. Custom roles can be assigned to members alongside built-in roles.

Account, Billing & More

Billing

Navigate to Account → Billing.

  • View current plan (Standard or Team Premium), cost, device count, renewal date
  • Upgrade or downgrade between plans; adjust device seat quantity
  • Switch billing interval (monthly / annual)
  • Manage in Stripe Portal — update payment method, view invoices
  • Cancel subscription or reactivate a cancelled plan
  • Team root admins: delegate license and AI credit pools to sub-organizations

Devices (License Slots)

Navigate to Devices in the sidebar (personal license management, not Fleet).

  • Shows how many of your subscription's device slots are in use
  • Lists active and revoked desktop and Android installations tied to your account
  • Remove Device frees a license slot for another installation
  • When all slots are used, an upgrade banner links to Billing

Proxies Marketplace

Navigate to Overview → Proxies.

  • Marketplace tab — purchase residential proxy bandwidth from Evomi (PAYG or Membership subscription)
  • My Products tab — manage accounts, view usage statistics, use the Proxy Generator
  • Proxy Generator: configure protocol, countries, session type, output format, and expert multipliers (ISP targeting, TCP fingerprint, etc.)

Account Settings

Navigate to Account → Settings.

  • Profile — view name and email (read-only)
  • Password — change account password
  • Two-Factor Authentication — enable TOTP (QR code + backup codes) or email OTP fallback
  • Sign Out — log out of the web dashboard
  • Delete Account — permanently delete account (requires password confirmation)

Referral Program

Navigate to Account → Referral to share your referral link and track commissions.

Download Client

Navigate to Overview → Download Client or visit /download. Windows and macOS installers are there; Android is on Google Play, with the APK as a fallback for phones without a store.

Frequently Asked Questions

Does the AI assistant see my proxy passwords?

No. The configuration summary sent with each message contains proxy names, hosts, ports, protocols and usernames — passwords are left out. If you paste a proxy string containing a password into the chat, it is masked before the request goes to the model. The one exception is images: an attached screenshot is forwarded as it is, so do not attach one that shows credentials. See AI Configuration Assistant.

Can the AI assistant change my configuration without asking?

No. Every proposed change — a proxy, a rule, a chain, a setting, or a whole policy in the web dashboard — appears as a card with an Apply button. Nothing is written to your configuration, and nothing is pushed to a device, until you click it. Organisation admins can also switch the assistant off entirely with Allow Using AI.

What's the difference between SOCKS4, SOCKS4a, and SOCKS5?

SOCKS4 supports TCP only and requires the client to resolve DNS locally (your ISP sees the domain lookup). SOCKS4a is an extension that lets the proxy resolve DNS instead — better for privacy. SOCKS5 supports both TCP and UDP, has built-in username/password authentication, and always resolves DNS remotely by default. For most use cases, SOCKS5 is recommended.

Which chain type should I use?

Simple if you need multi-hop anonymity (traffic passes through all proxies). Redundancy if you need high availability and want automatic failover to a backup proxy. Load Balancing if you want to distribute connections across multiple proxies (useful for scraping or rate-limit avoidance). Enable "Same proxy per PID" in Load Balancing if an application needs a stable IP across its session.

When will I see a TLS fingerprint warning?

On Windows, warnings appear when an application produces a TLS fingerprint (JA3 hash) that matches known automation tools or bot-like clients. For example: Python's requests library, plain curl, Go's net/http, or Selenium/Puppeteer produce recognizable fingerprints that anti-bot services can detect. Real browsers (Chrome, Firefox, Edge) produce normal fingerprints and don't trigger warnings. macOS and Android inspect TLS Client Hello bytes to recover a hostname when DNS did not; they do not show the Windows DETECTABLE / BLOCKED fingerprint cards.

How do I prevent DNS leaks?

Enable "Resolve host names through the proxy" in DNS settings. For maximum protection, also enable leak protection (IP Protection on Windows; the Leak Protection card on the macOS DNS page; Settings → Leak protection on Android), which blocks unsafe UDP fallback, IPv6 leaks, and forces strict DNS-over-proxy. On macOS, Block encrypted DNS discovery and Block known DoH endpoints stop Apple's DoH upgrade path and well-known resolvers. On Windows, consider disabling Smart Multi-Homed Name Resolution (registry setting) and your browser's Secure DNS (DoH).

What happens if all proxies in a chain fail?

For Redundancy chains: if "Connect directly if all fail" is enabled, traffic bypasses proxies and goes direct. If disabled (default), the connection is blocked entirely. Failed proxies are automatically rechecked at the configured interval (default: every 5 minutes). For Load Balancing chains: there's no automatic recheck — use the "Reset Fail Status" button or manually re-test proxies. For Simple chains: the entire chain fails if any single hop fails.

Can I use HTTP proxies for UDP traffic (QUIC/WebRTC)?

No. HTTP and SOCKS4 proxies only support TCP. UDP traffic (including QUIC/HTTP3, WebRTC, mDNS) cannot be routed through them. If "Block unsafe UDP fallback" is enabled in DNS settings, UDP from matched applications will be dropped rather than sent direct. Use SOCKS5 if you need UDP relay support — it's the only protocol that handles UDP natively.

How is bandwidth calculated for billing?

Bandwidth = total bytes (upload + download) through proxy connections. Traffic that bypasses the proxy (via Direct rules or split tunneling) is never counted. Protocol overhead (proxy headers) is included but typically negligible (<1%). The "Cost per GB" rate set on each proxy is used for cost calculation in the Monitoring page — this is separate from your ProxyTool subscription.

What does "Use Authentication URL" do?

Some enterprise proxies (like Blue Coat/Symantec) require web-based authentication instead of inline credentials. When enabled, ProxyTool authenticates by accessing the specified URL rather than sending username/password in the proxy protocol handshake. The URL can contain embedded credentials (scheme://user:pass@host) or trigger a browser-based auth flow. This automatically disables the regular credential prompts.

How does the Android app capture traffic?

Through a local VPN tunnel on the phone — not a ProxyTool VPN server. Every app enters the tunnel; rules then send traffic through a proxy, a chain, direct, or block it. Grant the VPN when you tap Start proxifying. Always-on VPN and lockdown live in Android Settings → VPN. Another VPN app cannot run at the same time. Full walkthrough: Android Getting Started.

How does the macOS app capture traffic?

Through a Network Extension (system extension) that macOS loads after you approve it — not a VPN server and not a Windows WFP driver. Settings → Engine → Install, then allow it in System Settings. The app must live in /Applications. After that, Start in the sidebar (or Start Routing on the Dashboard) puts every connection the extension sees through your rules. Full walkthrough: macOS Getting Started.

Can I migrate from Proxifier?

Yes — on Windows, macOS and Android. Go to Settings → Profiles → "Migrate from Proxifier" (macOS: Start Migration…; Android: Choose Proxifier profile…). Import your .ppx or .xml file. Windows DPAPI passwords need the same Windows account and cannot be decrypted on macOS or Android — re-enter them. On macOS, process names become bundle IDs where ProxyTool knows the match; edit the rest with Choose… or by typing the ID. On Android they map to packages; edit the rest with Choose installed apps.

Does ProxyTool work with all applications?

On Windows, yes — a WFP driver intercepts any process. On macOS, a Network Extension captures connections the same way; write rules against bundle identifiers (com.apple.Safari, com.google.Chrome). On Android, a local VPN tunnel captures every app; you then write rules against package names (com.android.chrome). Apps do not need their own proxy settings. ProxyTool's own traffic always goes direct so the engine cannot lock itself out. On Android, another VPN app cannot run at the same time.

What is the difference between a Policy and a Restriction?

A Policy defines the configuration deployed to devices — proxies, chains, rules, DNS, and per-platform app settings (Windows + Linux settings / macOS macosSettings / iOS + iPadOS iosSettings / Android androidSettings). Each platform receives only its own group; there is no inheritance. A Restriction controls what end users can see and change. Shared keys reach every device; desktop, Windows-only, macOS-only, iOS-only and Android-only keys are filtered on delivery. Both are assigned to device groups and delivered with the device's heartbeat.

Can I assign multiple policies to one group?

No. Each device group can have exactly one policy and one restriction. Assigning a new policy to a group that already has one triggers an override confirmation. To use a different policy, assign it from the Policy Editor or Policies list — the previous assignment is replaced.

What does Additive vs Override apply mode do?

Additive merges the pushed policy with existing local configuration — settings not covered by the policy remain on the device. Override replaces the entire device configuration with the policy content. Use Override for strict managed deployments; use Additive when devices may have local additions.

What happens when I hide Proxies vs lock Add Proxy?

Hide Proxies (UI Visibility) removes the Proxies page from the sidebar entirely — the user cannot see or access it. Allow Add Proxy (Permissions) keeps the page visible but blocks creating new proxies when turned OFF. You can combine both: hide the page for a clean UI, or show it but lock editing.

Standard vs Team Premium — what management features do I get?

Standard includes Fleet, Groups, Policies, and Automations. Team Premium adds Users & Roles, Device Restrictions, Permissions & Roles, and organization-level AI credit pool management. Upgrade from Account → Billing in the web dashboard.

How does policy push reach devices?

When you click Push & Release or Save & Apply, the server records the policy (or restriction) for every device in the assigned groups. Each device sends a heartbeat once a minute, collects what is waiting for it, applies the configuration and reports back in the same channel. Check Fleet for applied policy version and "Update pending" status if a device hasn't synced yet.

What is the difference between Fleet devices and License slots?

License slots (Devices page) track how many desktop installations your subscription allows — personal activations tied to your account. Fleet devices (Management → Fleet) are organization-managed endpoints enrolled for remote policy deployment, status monitoring, and restrictions. A device can be both a licensed installation and a fleet-managed device.

Where do I assign a policy to a group?

Assign from the Policy Editor → Summary tab or from the expanded policy row on the Policies list page. The Groups page shows assigned policy/restriction as read-only links — it does not perform assignments. The same applies to restrictions via the Restriction Editor → Assignments tab.

We use cookies to improve your experience and analyze site usage. See our Cookie Policy and Privacy Policy.