Why did the proxy check fail?
Use authentication, timeout, refused port, unsupported configuration, or failing-hop results to locate the problem.
Updated Aug 24, 2026MaskPilot runs proxy checks from the current device. A failure usually comes from incorrect node details, a service restriction, local network blocking, or one unavailable hop in a multi-hop route.
Identify the affected scope first
- Check another known-good node in the same group.
- If every node fails, inspect the local network, firewall, VPN, DNS, or corporate network policy first.
- If only one node fails, inspect that node’s protocol, address, port, credentials, and expiry.
- If individual nodes work but a route fails, run “Check full connection” and start with the first failing hop identified on the page.
Act on the diagnosis
Proxy authentication failed
- Copy the username and password again, checking spaces and letter case.
- Confirm whether the service uses an IP allowlist instead of credentials.
- Check whether the subscription or node has expired.
- If credentials contain special characters, use the complete URL from the provider or valid URL encoding.
Connection timed out
- Retest later to exclude a temporary network fluctuation.
- Confirm that the node accepts connections from the current region or source network.
- Rule out the local VPN, security software, or corporate network policy.
- Ask the provider whether the node is under maintenance.
Could not connect to the port
- Verify that the server address and port are not reversed or entered twice.
- Confirm that the selected protocol matches the provider instructions.
- An open port reported by another tool does not prove that the expected proxy protocol works.
Unsupported proxy configuration
- For a standard proxy, select only HTTP, HTTPS, or SOCKS5.
- For an advanced proxy, use “Check configuration” and confirm that it recognizes the protocol, server, and port.
- Do not paste a subscription web page, QR text, or routing rule as though it were a node configuration.
- To correct an advanced proxy, import the corrected configuration again.
Troubleshoot a multi-hop route
“Check full connection” adds nodes progressively in connection order. For example, “hop 2 is unavailable” means hop 1 works, but the connection through the first two hops cannot complete.
Check these items in order:
- Hop 1 can reach hop 2’s address and port.
- Hop 2 does not restrict the source IP unexpectedly.
- Authentication, TLS, and transport parameters are correct on every hop.
- No node in the route was deleted, expired, or replaced by the provider.
Run the full connection check again after changing any hop.
If it still fails
Keep the diagnosis type, failing hop number, and provider name shown on the page, and record the approximate check time yourself. Do not send a complete password or unredacted advanced configuration. Provide support with reproducible steps and a redacted address instead.
If “Check connection” succeeds but the pre-launch exit information check fails, follow the steps in “Why can’t a profile start after assigning a proxy?”