SOCKS5 proxy


Last updated: 25 August 2021

Using our SOCKS5 proxies can further minimize your computer's identity from being revealed and reduce CAPTCHAs. This guide explains why SOCKS5 is beneficial and how to use it.

What this guide covers


With the SOCKS5 proxy on all of Mullvad's VPN servers, you can further minimize your computer's identity from being revealed. This simple yet powerful feature also reduces CAPTCHAs.

For advanced users, the proxy is located on IP (OpenVPN) or (WireGuard), port 1080.

The SOCKS5 proxy is only accessible when you are connected to Mullvad.

Why the proxy is beneficial

Kill switch

You may already be familiar with the Mullvad app's built-in "kill switch" safety feature. In other words, in the event that the Mullvad connection is terminated, all of your Internet traffic is automatically blocked, ensuring that your traffic is not accidentally leaked outside of our secure tunnel.

However, what happens if you've forgotten to start the Mullvad app? This is where using the SOCKS5 proxy comes in handy, to act as back-up protection.

Reduced CAPTCHAs

Another benefit is a reduction in the amount of CAPTCHAs you will experience. Many websites and services require this identification when they detect traffic that originates from a VPN server. The proxy makes this detection more difficult.

Static IPv6 / IPv4 addresses

Each Mullvad server can have multiple exit IPs, but if you use the SOCKS5 proxy on the server then you will always get the same IP-address - that of the proxy. This can be useful if you need to whitelist your Mullvad IP somewhere. The proxy provides you with an IPv6 address and an IPv4 address. You can find them on our Connection Check page.

How the proxy works

If you configure your browser, for example, to use the SOCKS5 proxy, it will direct all of your internet access via the proxy which is only accessible through Mullvad. So if you haven't turned on the app, your browser will prevent all internet access and therefore won't leak any information.

The proxy also works with routers and any other VPN used together with Mullvad's servers.

Get started with the SOCKS5 proxy

Follow these steps to configure your web browser to use our SOCKS5 proxies.

If you are using WireGuard, you will need to replace with in the instructions below.

Firefox – newer versions

  1. In a Firefox browser window, click the menu button in the top right corner and choose Options or Preferences.
  2. In the search box, type “network”, then click on the Settings button in the result.
  3. Select Manual proxy configuration.
  4. Make sure that the HTTP Proxy, HTTPS Proxy and FTP Proxy fields are empty.
  5. In the SOCKS Host field, enter and enter 1080 in the Port field.
  6. Click on SOCKS v5
  7. Tick Proxy DNS when using SOCKS v5.
  8. Click on OK.


To disable, go to step #5 and change the setting to No Proxy.

Firefox – older versions

  1. In the Firefox menu, click on Edit.
  2. Click on Preferences.
  3. Click on Advanced.
  4. Click on Network Settings.
  5. Select Manual proxy configuration.
  6. Make sure HTTP/SSL and FTP proxy fields are empty.
  7. In the SOCKS Host: field, enter with port 1080.
  8. Click on SOCKS v5 and enable Remote DNS or tick Proxy DNS when using SOCKS v5.
  9. Click on OK.

To disable, go to step #5 and change the setting to No Proxy.

Android - Firefox

Note: The about:config settings page was removed from Firefox on Android and they are currently only available in Firefox Nightly (the development version of Firefox).

  1. Enter about:config in the address bar and click on Send.
  2. In the search field, enter proxy.
  3. Scroll down to network.proxy.socks and enter
  4. Scroll down to network.proxy.socks_port and enter 1080.
  5. Change the value for network.proxy.socks_remote_dns to True.
  6. Change the value for network.proxy.socks_version to 5.
  7. Change network.proxy.type to 1.
  8. Clear the field for network.proxy.ftp.
  9. Clear the field for network.proxy.http.
  10. Clear the field for network.proxy.ssl.
  11. Click on the back button to save the changes.

 To disable, go to step #7 and change the setting to 5.

Windows - Chrome / Edge / Brave

Right click on your desktop shortcut to Chrome, Edge or Brave and select Properties. Then add the following to the end of the Target (the field in the top) after the text that is already there. Make sure to first put one empty space after the current text and then add this:

When using WireGuard protocol:


When using OpenVPN protocol:


Then click on OK.

Linux - Chromium

This works with Brave and other Chromium based browsers. Start it from a Terminal like so:

brave-browser --proxy-server=socks5://

chromium-browser --proxy-server=socks5://

For OpenVPN use instead of which is for WireGuard.

Note: The --proxy-server flag applies to URL loads only. There are other components of Chrome which may bypass the proxy server. To address this add the flag --host-resolver-rules="MAP * ~NOTFOUND , EXCLUDE".

macOS - Safari / Chrome / Edge / Brave

To add the SOCKS5 proxy to Safari, Chrome, Edge or Brave in macOS you open System Preferences > Network > click on the active (green) connection > Advanced... > Proxies > check "SOCKS Proxy" and enter the following.

When using WireGuard protocol:

SOCKS Proxy Server: : 1080

When using OpenVPN protocol:

SOCKS Proxy Server: : 1080

Testing the connection

Go to the Mullvad Connection Check to see if the web browser is using the proxy. Expand the top left box with the down arrow and look for the words "SOCKS through".

WireGuard and SOCKS5

All WireGuard servers have two SOCKS5 proxies listening on them:

  • The SOCKS5 proxy on port 1080 is not reachable from other WireGuard servers.
  • The SOCKS5 proxy on 10.124.0.x to 10.124.1.x on port 1080 are reachable from other WireGuard servers. These IPs are unique for each WireGuard server. For instance, is and is

To configure the one you want to use, follow the directions listed for Firefox or Qbittorrent but use instead of as the SOCKS5 host.

Multihop with SOCKS5

You can also use the SOCKS5 proxies to multihop. To do so, you can configure your browser or other program to exit from a server that is different from the one you connected to.

For instance, if you are connected to and then want to exit via, you would configure your browser/program to use on port 1080 as your exit node.

To use it in Firefox see our blog post SOCKS for expats.

You can also try this in a terminal (in the following examples, we are connected to se1-wireguard):

Without SOCKS5 proxy

Note that the Mullvad VPN server will assign one of multiple possible exit IPs.


With SOCKS5 proxy on the connected Mullvad VPN server

Note that the proxy has a different exit IP. Each proxy has only one exit IP.

curl --socks5-hostname

With SOCKS5 proxy running on a different Mullvad VPN server

Note that you will get the exit IP from the proxy on the other Mullvad VPN server.

curl --socks5-hostname

With SOCKS5 proxy - IPv6 exit IP

Each proxy also has one IPv6 exit IP.

curl --socks5-hostname

Additional information


"WireGuard" is a registered trademark of Jason A. Donenfeld.