Introduction: What You'll Get

If you work with mobile proxies on a Mac, sooner or later you hit the same situation. You enter the address and port in your Wi-Fi settings, a website shows a new IP, and you're thrilled. Then it turns out Terminal is downloading packages directly, git is using the old address, and half your apps didn't even notice the change. This guide solves the problem completely.

After reading and following all the steps, you'll have a proxy on macOS that works on three levels at once:

  • At the system level: Safari, Chrome, Mail, messengers, and other apps that respect system settings.
  • At the Terminal level: networksetup commands to turn the proxy on, off, and switch it without a single mouse click.
  • At the developer tools level: curl, git, Homebrew, pip, npm, and other utilities that read environment variables, not system settings.

We'll also go over the exception list separately. That's the field that causes some traffic to bypass the proxy even though you didn't intentionally set anything up. You'll understand how it works, what to add, what to remove, and how to verify that no request slips through directly where it shouldn't.

Who This Guide Is For

This guide is written for beginners. If you've never opened Terminal, don't worry: we'll go through each command letter by letter and explain what it does. This guide will be useful for:

  • marketers and SMM specialists managing multiple projects from different IPs;
  • arbitrage professionals who need to quickly switch geos and test creatives;
  • developers testing apps and APIs through mobile proxies;
  • business owners who want to figure it out once and not call a specialist every time they change proxies.

For experienced users, there's a block at the end with advanced techniques: network locations, PAC files, shell aliases, and automated rotation scripts.

What You Need to Know Beforehand

Nothing complicated. You just need to be able to open System Settings and copy text. Everything else is explained along the way. We don't cover settings for specific browsers or antidetect browsers: there are separate articles on those in the blog. Here we focus only on macOS as a system and its built-in tools.

How Much Time It Takes

Basic setup through System Settings takes 10 minutes. Setting up Terminal and developer tools takes another 15-20 minutes. Full verification and going through exceptions takes about 10 minutes. Total: 30-40 minutes if you do everything calmly with checks.

Preliminary Preparation

Before changing anything on your system, let's gather everything we need. Good preparation saves more time than any life hack.

What You'll Need

  • A Mac with macOS Ventura 13 or later. All examples are tested on macOS Sonoma 14, Sequoia 15, and Tahoe 26. On older versions where System Settings looks like a grid of icons, the path to proxy settings is slightly different, and we'll point that out separately.
  • Mobile proxy details. This includes the server address (domain or IP), port, username, and password. Mobile proxies usually have two ports: one for HTTP and one for SOCKS5. Keep both handy.
  • The IP rotation link if your provider gives you one. You'll need it in the automation section.
  • Administrator rights on your Mac. To change system proxy via Terminal, macOS will ask for your user password.
  • A text editor for notes. The built-in TextEdit or Notes will do.

What to Check Before You Start

  1. Make sure your internet works without a proxy. Open any website in Safari. If it doesn't load, fix your network first, otherwise you won't know what broke later.
  2. Find out which interface you're connected through: Wi-Fi or Ethernet cable. Open System Settings, then Network. The active connection is marked with a green dot and the word Connected. Write down the name: usually Wi-Fi or Ethernet.
  3. Check your current IP without a proxy. Open any IP-checking service in your browser and write down the address. We'll compare results with it.

Backup Your Current Settings

Proxy settings in macOS are easy to revert, but it's better to record the initial state. Especially if you're on a corporate Mac where the system administrator may have set something up in advance.

  1. Open Terminal. Press Command and Space, type Terminal, and press Enter.
  2. Copy and paste the following command, then press Enter:
scutil --proxy > ~/Desktop/proxy_backup.txt

A file called proxy_backup.txt will appear on your Desktop with a full description of your current proxy settings. If you mess something up, you can always compare values with this file.

Tip: Immediately create a note in Notes with your proxy details: host, HTTP port, SOCKS5 port, username, password, rotation link. You'll refer to it dozens of times. Don't store the password in plain text in shared documents.

Basic Concepts: What You Need to Understand First

Here are a few terms without which the following steps will seem like magic. This is a must-read, even if you think you already know them.

Proxy Server

This is an intermediary between your Mac and the internet. Instead of going directly to a website, your request first goes to the proxy server, and from there to the site. The site sees the proxy's IP address, not yours. A mobile proxy is different because its IP belongs to a cellular carrier, so to websites you look like a regular smartphone user.

HTTP Proxy and SOCKS5 Proxy

These are two different ways of communicating with a proxy server. HTTP proxy understands web traffic, works with websites and most apps. In macOS, it's split into two toggles: Web Proxy (HTTP) for regular sites and Secure Web Proxy (HTTPS) for encrypted sites. In practice, you enter the same address and port in both fields.

SOCKS5 proxy works lower, at the connection level, and passes any traffic, not just web. It's useful for Terminal, messengers, and games. An important macOS nuance: system settings let you specify a username and password for SOCKS, but many apps don't support that authentication through system SOCKS. That's why we'll use HTTP in system settings and leave SOCKS5 for Terminal and specific apps.

System Proxy

These are settings stored in macOS for a specific network interface. Safari, Chrome, Mail, App Store, and most Swift and Objective-C apps read them automatically. But not all. Apps written in Python, Go, Node.js, and classic Unix utilities like curl and git ignore system settings. They look at environment variables.

Environment Variables

These are named values that live in your Terminal session. For example, the http_proxy variable tells utilities: send all HTTP traffic here. Variables only exist in the open Terminal window unless you write them to a shell configuration file. There's a separate step for that.

Exception List

In macOS, it's called "Bypass proxy settings for these Hosts & Domains". All addresses in this list are sent directly by the system, bypassing the proxy. By default, it already contains *.local and 169.254/16, which handle local network and should not be removed. Problems start when extra masks end up in the list or when you expect exceptions to work in Terminal. They won't: Terminal has its own list, the no_proxy variable. We'll cover all of this.

Network Service

This is what macOS calls each interface: Wi-Fi, Ethernet, Thunderbolt Bridge, iPhone USB. Proxy is configured separately for each service. If you set it up for Wi-Fi and then plug in a cable, the proxy stops working. This is one of the most common reasons why a proxy on macOS works sometimes and not others.

Step 1: Verify Proxy Details Before Setting Up the System

Goal of this step: make sure the proxy is alive and the username and password are correct. This will save you half an hour of searching for a mistake in settings when the problem was a typo in the password.

We'll test using curl. This utility is already on macOS, no need to install anything.

  1. Open Terminal if it's not already open.
  2. Take the proxy details from your note. For this example, we'll use placeholder values: host proxy.example.net, HTTP port 10000, SOCKS5 port 10001, username user123, password pass456. Replace these with your real data.
  3. Enter the command to test the HTTP port and press Enter:
curl -x http://user123:pass456@proxy.example.net:10000 https://ifconfig.me

Let's break down what's written here. The -x flag tells curl the proxy address. Then comes the protocol http, then username, colon, password, at symbol, host, colon, port. At the end is the address of the service that returns the IP from which the request came.

  1. After 1-3 seconds, an IP address will appear in Terminal. This is your mobile proxy's IP. If it differs from what you recorded during preparation, everything works.
  2. Now test the SOCKS5 port with the same command, changing the protocol and port:
curl -x socks5h://user123:pass456@proxy.example.net:10001 https://ifconfig.me

Note the letter h in socks5h. It means domain names will be resolved on the proxy side, not on your Mac. For mobile proxies, this is the correct option: you don't leave DNS requests to your home ISP.

Warning: If your password contains the at symbol, colon, slash, hash, question mark, or percent sign, they need to be encoded. Replace at with %40, colon with %3A, hash with %23, question mark with %3F, percent with %25. Otherwise curl will split the string incorrectly and think the password ended early.

Possible Issues at This Step

  • Response: Received HTTP code 407 from proxy after CONNECT. The proxy rejects authentication. Check your username and password, look for special characters. Make sure IP-based authentication isn't enabled in your provider's dashboard instead of username/password.
  • Response: Failed to connect or Connection timed out. Wrong host or port, or the proxy is off. Check your dashboard. Try another port.
  • The command hangs with no output. Wait 30 seconds. Mobile networks are sometimes slow. If nothing happens, press Control and C to interrupt and check your data.

Verification: Both curl commands returned an IP address different from your home IP. You can move on. If even one didn't work, it's pointless to continue: the system will use the same data.

Step 2: Set Up Proxy via macOS System Settings

Goal of this step: make Safari, Chrome, and all apps that respect system proxy go online through your mobile proxy.

Open the Right Screen

  1. Click the Apple icon in the top-left corner of your screen and select System Settings.
  2. In the left column, click Wi-Fi if you're connected wirelessly. If you're using a cable, click Network, then Ethernet.
  3. Find your network name. To its right, there's a Details button with three dots or a label. Click it.
  4. A window with connection parameters opens. In the left column of that window, select Proxies. It's at the very bottom of the list, after TCP/IP, DNS, and WINS.

You'll see a list of toggles: Auto Proxy Discovery, Automatic Proxy Configuration, Web Proxy (HTTP), Secure Web Proxy (HTTPS), FTP Proxy, SOCKS Proxy, Streaming Proxy (RTSP), Gopher Proxy. At the bottom is the "Bypass proxy settings for these Hosts & Domains" field.

If you're on an older macOS where System Settings looks like a grid of icons, the path is: System Settings, Network, select the interface on the left, click Advanced, then the Proxies tab. The rest is the same.

Enable HTTP Proxy

  1. Click the toggle for Web Proxy (HTTP). It turns blue, and input fields appear below.
  2. In the Server field, enter your proxy host, e.g., proxy.example.net. No http://, no slashes, just the host.
  3. In the Port field on the right, enter the HTTP port, e.g., 10000.
  4. Turn on the "Proxy server requires password" toggle.
  5. In the Username field, enter your username. In the Password field, enter your password. Here you don't need to encode special characters; enter them as is.

Enable HTTPS Proxy

Most websites today use HTTPS, so this step is mandatory. Without it, encrypted traffic goes directly, and you'll wonder why some sites see the proxy and others see your real IP.

  1. Click the toggle for Secure Web Proxy (HTTPS).
  2. Enter the same host and the same port as for HTTP. Mobile proxies handle both types of traffic on one port.
  3. Turn on "Proxy server requires password" and enter your username and password again.

About SOCKS Proxy and Other Toggles

Leave the SOCKS Proxy toggle off in system settings if you have HTTP and HTTPS enabled. The reason is that with system SOCKS enabled, some apps start preferring it, but not all support authentication through system SOCKS. The result: some apps lose network access. Don't touch FTP, RTSP, and Gopher; they're outdated protocols. Also leave Auto Proxy Discovery and Automatic Proxy Configuration off, otherwise they might override your manual values.

Save

  1. Click the OK button in the bottom-right corner of the window.
  2. If the system asks for your Mac user password, enter it. This is normal: changing network settings requires admin rights.
  3. Completely close Safari or Chrome and reopen them. Browsers cache proxy settings on launch.

Tip: On the first request through the proxy, macOS may show a system dialog asking for your proxy username and password, even if you already entered them. Enter the data and check "Remember in keychain." After that, the dialog won't appear again.

Verification: Open an IP-checking service in Safari. The address should match what curl returned in Step 1. Also check a page that shows your carrier: it should display a mobile carrier, not your home ISP.

Possible Issues

  • Sites don't open at all. Check that you enabled HTTP and HTTPS, not FTP or SOCKS. Check the port. Temporarily turn off both toggles and make sure the internet comes back: that way you'll know the issue is with proxy settings, not the network.
  • The password dialog keeps popping up. The password is entered incorrectly or has a trailing space from copying. Clear the field and type the password manually again.
  • IP didn't change. You probably configured the wrong interface. Go back to Network and check which service is marked as Connected.

Step 3: Set Up the Exception List Correctly

Goal of this step: understand what traffic the system bypasses the proxy for, and set up the list so local services work and external traffic doesn't leak.

The "Bypass proxy settings for these Hosts & Domains" field is at the bottom of the Proxies screen. By default, it contains: *.local, 169.254/16. Many users either ignore it or start adding everything to it.

How to Read the List

  • *.local means all addresses ending in .local. These are devices on your home network: printer, network drive, other Macs. They can't be opened through an external proxy, so this entry is necessary.
  • 169.254/16 means the range of service addresses that a Mac assigns to itself when it doesn't get an address from the router. Also local stuff.
  • Entries are separated by commas. Spaces after commas are allowed.
  • An asterisk replaces any part of a name. The entry *.example.com excludes all subdomains of example.com, but not example.com itself. For that, you need a separate entry.
  • You can specify IP addresses and subnets in address/mask format, e.g., 192.168.0.0/16 for your entire home network.

What to Add

  1. Click in the exceptions field after the last entry.
  2. Add localhost and 127.0.0.1 separated by commas. Without them, local web servers and admin panels on your Mac will try to go through the mobile proxy and fail.
  3. If you use home devices by IP, add your local subnet. Usually it's 192.168.0.0/16 or 10.0.0.0/8. You can find your local address on the TCP/IP screen in the same window.
  4. Click OK.

The final list for most users looks like this: *.local, 169.254/16, localhost, 127.0.0.1, 192.168.0.0/16.

What Not to Add

Here's where the title's "bypassing exceptions" comes in. We're talking about situations where traffic bypasses the proxy not because you wanted it to, but because the list was carelessly composed.

  • Don't enter a single asterisk or *.com. Such a mask will disable the proxy for almost the entire internet, while the toggles remain blue and you'll think everything works.
  • Don't enter domains of services you work with. If you add *.facebook.com to speed up loading, the site will see your real IP. For multi-accounting tasks, this is critical.
  • Don't enter the proxy host itself. It makes no sense: the connection to the proxy goes directly anyway.
  • Don't remove *.local and 169.254/16. AirDrop, printing, and router access will break.

Warning: The exception list in system settings only affects apps that use the system proxy. Terminal, curl, git, and Python scripts don't see it. They have their own list, the no_proxy variable, and it's configured separately. We'll get to it in Step 5. If you expect an entry in the system list to affect a script, you'll be disappointed.

Tip: Periodically open the exception list and check it with your eyes. Some corporate utilities and device management agents add their domains during installation. Spotting an extra mask like *.com in ten seconds is easier than searching for the cause of an IP leak for a week.

Verification: Open http://localhost or any local page you have in your browser. It should open instantly without a proxy error. Then open an external IP-checking service: it should still show the mobile proxy IP.

Step 4: Manage Proxy from Terminal with networksetup

Goal of this step: learn to turn the system proxy on, off, and change it with one command, no mouse, no ten clicks in settings. This is the skill that pays back the time spent reading this section within a month.

macOS has a built-in utility called networksetup. It does exactly what System Settings does, but from the command line. Everything you set up in Step 2 can be repeated, changed, or undone with one line.

Find the Exact Network Service Name

  1. In Terminal, enter the following command and press Enter:
networksetup -listallnetworkservices

You'll see a list like: Wi-Fi, Ethernet, Thunderbolt Bridge, iPhone USB. Find the one you're connected through. In the following commands, we'll use Wi-Fi. If your service has a different name, substitute it. If the name contains a space, e.g., Thunderbolt Bridge, enclose it in double quotes.

Check Current Settings

networksetup -getwebproxy Wi-Fi

You'll see four lines: Enabled: Yes or No, Server, Port, Authenticated Proxy Enabled. If you completed Step 2, Enabled will be Yes, and the server and port will match what you entered. Similarly for HTTPS:

networksetup -getsecurewebproxy Wi-Fi

Enable HTTP and HTTPS Proxy with One Command

The command format: networksetup, action, service, host, port, enable authentication, username, password.

networksetup -setwebproxy Wi-Fi proxy.example.net 10000 on user123 pass456
networksetup -setsecurewebproxy Wi-Fi proxy.example.net 10000 on user123 pass456

Enter both commands one after the other. After each, the system may ask for your Mac user password. Enter it; characters won't be displayed, that's normal. Press Enter.

The word on after the port enables authentication. If your proxy uses IP authentication instead of username/password, write off and don't specify username and password.

Turn Proxy Off and On Without Losing Settings

The most useful pair of commands. They don't erase the host and port, just flip the switch:

networksetup -setwebproxystate Wi-Fi off
networksetup -setsecurewebproxystate Wi-Fi off

To turn it back on, replace off with on. This way you can switch your Mac to direct connection and back in two seconds.

Manage the Exception List from Terminal

View the current list:

networksetup -getproxybypassdomains Wi-Fi

Set a new list entirely. The command replaces all entries, so list the full set separated by spaces:

networksetup -setproxybypassdomains Wi-Fi "*.local" "169.254/16" localhost 127.0.0.1 "192.168.0.0/16"

Put entries with asterisks and slashes in quotes so the shell doesn't try to interpret them. You can clear the list entirely with the word Empty instead of domains, but remember: then local addresses will go through the proxy and stop working.

Universal View Command

The scutil utility shows all proxy settings in one place, including exceptions:

scutil --proxy

Look for lines HTTPEnable, HTTPProxy, HTTPPort, HTTPSEnable, ExceptionsList. A value of 1 means on, 0 means off. We used this command for the backup.

Tip: Open System Settings on the Proxies screen and run any networksetup command in Terminal next to it. You'll see the toggles change in real time. This is the best way to make sure Terminal and the GUI manage the same data.

Possible Issues

  • Error: Wi-Fi is not a recognized network service. The service has a different name. Run networksetup -listallnetworkservices and copy the exact name.
  • The command ran but nothing changed in settings. Close and reopen the System Settings window; it doesn't always refresh instantly.
  • It asks for a password and says Sorry, try again. You're entering your Mac user password, not the proxy password. Characters aren't displayed; just type and press Enter.

Verification: Run networksetup -setwebproxystate Wi-Fi off, refresh the IP-checking service in your browser, and you'll see your home IP. Run the same command with on, refresh the page, and you'll see the proxy IP. If switching works both ways, this step is done.

Step 5: Set Up Proxy for curl, git, Homebrew, pip, and npm

Goal of this step: make command-line tools work through the proxy. This is where most traffic leaks because these programs don't look at system settings.

Why System Proxy Doesn't Work Here

Utilities like curl, wget, git, pip, npm, and brew are written to work on all Unix systems. They don't know about macOS and its System Settings. Instead, they read environment variables named http_proxy, https_proxy, all_proxy, and no_proxy. If the variables aren't set, traffic goes directly. The toggles in settings can be blue all they want.

Temporary Enable in the Current Terminal Window

Enter these three commands one by one:

export http_proxy=http://user123:pass456@proxy.example.net:10000
export https_proxy=http://user123:pass456@proxy.example.net:10000
export no_proxy=localhost,127.0.0.1,*.local

The first directs HTTP traffic to the proxy. The second directs HTTPS traffic there too. Note: in the https_proxy value, the protocol is still http because that's the protocol for communicating with the proxy, not with the site. The third sets exceptions for Terminal. That's the separate list we talked about in Step 3.

Some programs only read variables in uppercase. To avoid guessing, set those too:

export HTTP_PROXY=$http_proxy HTTPS_PROXY=$https_proxy NO_PROXY=$no_proxy

Now test without the -x flag:

curl https://ifconfig.me

If it returns the proxy IP, the variables work. All programs launched from this Terminal window will now go through the mobile proxy. Close the window and the variables disappear.

Permanent Enable via Shell Configuration File

On modern macOS, the default shell is zsh, and its settings are stored in the .zshrc file in your home folder. Everything written there runs every time you open a new Terminal window.

  1. Open the file in the nano editor with:
nano ~/.zshrc
  1. Use the arrow keys to go to the end of the file.
  2. Paste the export lines from the previous section.
  3. Press Control and O, then Enter to save. Press Control and X to exit.
  4. Apply changes without restarting:
source ~/.zshrc

Warning: The password is stored in plain text in .zshrc. If the Mac is shared or you keep the file in cloud sync, think twice. There's a compromise in the advanced settings block: aliases that turn the proxy on with a short command instead of automatically.

Git

Git can read environment variables, but it's more reliable to set it in its configuration:

git config --global http.proxy http://user123:pass456@proxy.example.net:10000

To disable:

git config --global --unset http.proxy

This setting affects clone, pull, and push operations over HTTPS. For SSH access to repositories, you need a different approach, covered in the advanced block.

Homebrew

Brew relies entirely on environment variables. If you set them in .zshrc, nothing else is needed. Test with brew update: the update should complete without connection errors.

pip

The Python installer also reads environment variables. For a one-time run through the proxy without variables, use the flag:

pip install --proxy http://user123:pass456@proxy.example.net:10000 requests

npm

The Node.js package manager stores settings separately:

npm config set proxy http://user123:pass456@proxy.example.net:10000
npm config set https-proxy http://user123:pass456@proxy.example.net:10000

To disable: npm config delete proxy and npm config delete https-proxy.

SOCKS5 for Terminal

If you want to route terminal traffic through the SOCKS5 port, instead of http_proxy and https_proxy, set one variable:

export all_proxy=socks5h://user123:pass456@proxy.example.net:10001

Curl and many utilities understand it. But not all: git over HTTPS doesn't always read the all_proxy variable, and pip doesn't understand SOCKS without an extra package. For universality, we recommend the HTTP option for beginners.

Tip: Add the line alias myip='curl -s https://ifconfig.me; echo' to .zshrc and then type myip to see the current Terminal IP in a second. This saves dozens of checks a day.

Verification: Open a new Terminal window. Run curl https://ifconfig.me and git config --global --get http.proxy. The first command returns the proxy IP, the second shows the proxy address. That means the tools are configured and settings survive a restart.

Step 6: Find Traffic That Bypasses the Proxy and Fix It

Goal of this step: make sure no app in your workflow goes online directly without your knowledge. Here we systematize all causes of leaks and check each one.

Cause 1: App with Its Own Proxy Settings

Some programs ignore system proxy and environment variables because they have their own settings. Classic examples: Telegram Desktop, Firefox, Discord, some email clients, torrent clients, antidetect browsers. Each has a Network or Proxy section in its settings.

  1. Make a list of apps you work with.
  2. Open each and find the network settings section. If there's an option "Use system proxy settings," select it. If there's only manual input, enter host, port, username, and password.
  3. Check the IP inside the app if it allows, or through an IP-checking service opened in that app.

Settings for specific browsers and antidetect browsers are covered separately in the blog; we won't repeat them here. The important thing is to understand the principle: for each app, you need to check where it gets the proxy from.

Cause 2: App Launched Not from Terminal

Environment variables from .zshrc only affect programs launched from Terminal. If you launch a script by double-clicking, through a code editor, or a scheduler, the variables won't be picked up. Solution: set the proxy inside the script explicitly, or launch the script from Terminal, or specify variables in your code editor's settings.

Cause 3: Wrong Network Service

You set up Wi-Fi, but the Mac connected via cable because you plugged in a dock. Or vice versa. Simple check: networksetup -listallnetworkservices will show all services, and the Network section in settings will highlight the active one. Configure the proxy for each service you use. Repeat the networksetup commands from Step 4, replacing Wi-Fi with Ethernet.

Cause 4: Extra Masks in the Exception List

We talked about this in Step 3. Run networksetup -getproxybypassdomains Wi-Fi and make sure there's no single asterisk, masks like *.com, *.ru, *.net, or domains of work services. Do the same check in the no_proxy variable with echo $no_proxy.

Cause 5: IPv6

If your home ISP provides an IPv6 address and the proxy works over IPv4, some apps may try to go over IPv6 directly. For system apps this is rare, but for utilities it happens. Check that the IP-checking service doesn't show a long address with colons. If it does, open the service settings, TCP/IP tab, and switch Configure IPv6 to Link-Local Only.

Cause 6: HTTPS Enabled but HTTP Not, or Vice Versa

In system settings, these are two independent toggles. Forget one, and half your traffic leaks. Run scutil --proxy and make sure both HTTPEnable and HTTPSEnable are 1.

Cause 7: Browser Cache and Open Connections

A browser that was running before the settings change may hold old connections for a few more minutes. Completely close the app with Command and Q, not the red X, and reopen.

Tip: Do a control sweep. Open an IP-checking service in Safari, in Chrome, via curl in Terminal, and inside each work app. Write down four results side by side. If all match the mobile proxy IP, there are no leaks. Repeat this sweep after every proxy change or system update.

Verification: All control points from the list above show the same mobile proxy IP. Local addresses open directly. No toggle was accidentally left off.

Verifying the Result: Final Checklist

Go through the list and check each item. If one doesn't hold, go back to the corresponding step.

System Level

  • In System Settings on the Proxies screen, Web Proxy (HTTP) and Secure Web Proxy (HTTPS) are enabled, both with the same host and port.
  • Authentication is on, username and password are saved, the password dialog no longer appears.
  • Safari shows the mobile proxy IP and mobile carrier.
  • The exception list contains *.local, 169.254/16, localhost, 127.0.0.1, and your local subnet. No extra masks.
  • Local addresses open without errors.

Terminal

  • The command networksetup -getwebproxy Wi-Fi shows Enabled: Yes and the correct server.
  • The on/off commands via networksetup work both ways.
  • In a new Terminal window, echo $http_proxy outputs the proxy address.
  • curl https://ifconfig.me without the -x flag returns the proxy IP.
  • echo $no_proxy shows the list of local exceptions.

Tools

  • git config --global --get http.proxy returns the proxy address.
  • brew update completes without connection errors.
  • npm config get proxy returns the proxy address if you work with Node.js.
  • All work apps with their own network settings are switched to system proxy or configured manually.

How to Test End-to-End

  1. Turn off the system proxy with networksetup -setwebproxystate Wi-Fi off and networksetup -setsecurewebproxystate Wi-Fi off.
  2. Refresh the IP-checking service in your browser. Your home IP should appear.
  3. Run curl https://ifconfig.me in Terminal. The proxy IP should remain because Terminal uses variables, not system settings. This confirms the levels are independent.
  4. Turn the system proxy back on. Refresh the browser. The proxy IP should return.
  5. Open a new Terminal window, run unset http_proxy https_proxy, and curl again. Now Terminal will show your home IP. Close the window: in the next one, variables will be picked up from .zshrc again.

If each transition gave the expected result, you fully control the proxy on macOS at all levels. That was the goal.

Common Mistakes and Solutions

Proxy Is On but IP Doesn't Change

Cause: wrong network interface configured, or only one of HTTP and HTTPS toggles is on, or the browser wasn't restarted.

Solution: check the active service in Network, run scutil --proxy and make sure both Enable values are 1, completely close the browser with Command and Q.

Password Dialog Keeps Appearing

Cause: error in username or password, extra space after pasting, or old data from a previous proxy saved in Keychain.

Solution: clear the fields and re-enter manually. Open the Keychain Access app, find the entry with the proxy host, and delete it, then enter the data again and check "Remember."

Some Sites Open Through Proxy, Some Directly

Cause: only HTTP or only HTTPS is on, or a broad mask appeared in the exception list.

Solution: enable both toggles. Check the exception list with networksetup -getproxybypassdomains and remove anything not related to the local network.

Terminal Ignores Proxy Even Though System Is Configured

Cause: command-line utilities don't read system settings. Environment variables aren't set or are set in a different window.

Solution: add the export lines to .zshrc and run source ~/.zshrc. Check echo $http_proxy.

Error 407 Proxy Authentication Required

Cause: the proxy doesn't accept the username and password. Often it's special characters in the password inside the URL string.

Solution: encode special characters: at as %40, colon as %3A, hash as %23. Make sure IP-based authentication isn't enabled in your provider's dashboard.

Local Services, Printer, or Router Stopped Working

Cause: *.local and 169.254/16 were removed from the exception list, or localhost and the local subnet weren't added.

Solution: restore the list with networksetup -setproxybypassdomains with the full set of entries from Step 3.

After Restarting Mac, Proxy in Terminal Disappeared

Cause: variables were set only with export in an open window, not in .zshrc.

Solution: open nano ~/.zshrc, add the lines, and save. If you use another shell, e.g., bash, the file is called .bash_profile.

Everything Worked, Then Broke After a macOS Update

Cause: major system updates sometimes reset or rename network service settings.

Solution: open the proxy_backup.txt file on your Desktop, compare values, and repeat Step 4 with networksetup commands. Check the list of services: a new one may have appeared.

Slow Page Loading

Cause: this is normal for mobile proxies; cellular networks are slower than home ISPs. But sometimes it's because both HTTP proxy and SOCKS are enabled, and apps try to establish connections twice.

Solution: turn off system SOCKS, leave only HTTP and HTTPS. If speed is still low, try changing the IP via the rotation link.

Advanced Tips for Power Users

Basic setup is done. Here are a few tricks to turn manual work into a convenient system.

Network Locations: Two Profiles, One Switch

macOS lets you create multiple sets of network settings and switch between them entirely. This is more convenient than flipping toggles every time.

  1. Open System Settings, Network section.
  2. Click the three-dot button at the bottom of the services list and select Locations, then Edit Locations.
  3. Click the plus, name the new location Proxy. Click Done.
  4. Select the created location in the list. Configure the proxy for Wi-Fi and Ethernet as in Step 2.
  5. Leave the original Automatic location without a proxy.

Now you can switch via the Apple menu, Location item, or with a Terminal command:

networksetup -switchtolocation Прокси

And back: networksetup -switchtolocation Автоматически. All services switch at once, no more wrong-interface errors.

Aliases for Quick On/Off in Terminal

If you don't want to keep the proxy always on, add two functions to .zshrc instead of direct exports:

proxyon() { export http_proxy=http://user123:pass456@proxy.example.net:10000; export https_proxy=$http_proxy; export no_proxy=localhost,127.0.0.1,*.local; echo Proxy ON; }
proxyoff() { unset http_proxy https_proxy all_proxy no_proxy HTTP_PROXY HTTPS_PROXY; echo Proxy OFF; }

After source ~/.zshrc, the proxyon command enables the proxy in the current window, proxyoff disables it. The password is still in the file, but the proxy doesn't activate without your decision.

One Command for System and Terminal

Extend the proxyon function by adding lines networksetup -setwebproxystate Wi-Fi on and networksetup -setsecurewebproxystate Wi-Fi on inside it. Then one command turns on the proxy for both browsers and Terminal. Add the same commands with off in proxyoff. The system will ask for the admin password once per session.

Changing Mobile Proxy IP from Terminal

Most mobile proxy providers give a link for changing IP. You can trigger it via curl without opening a browser:

curl -s "https://rotation-address-from-dashboard"

Wrap it in a newip function and add it to .zshrc. The combination newip, then myip will show the new address in two seconds. For arbitrage professionals running dozens of checks a day, this is a significant time saver.

SSH Through SOCKS5 Proxy

If you connect to servers via SSH and want the connection to go through the mobile proxy, add this block to ~/.ssh/config:

Host myserver
 HostName 203.0.113.10
 ProxyCommand nc -X 5 -x proxy.example.net:10001 %h %p

The nc utility is built into macOS. The -X 5 flag means SOCKS5, the -x flag sets the proxy address. nc doesn't support username/password authentication, so this method works for proxies with IP authentication.

PAC File for Flexible Rules

The Automatic Proxy Configuration toggle accepts a PAC file address: a JavaScript script that decides for each address whether to go through the proxy or directly. This is a way to implement complex exceptions that can't be expressed with masks. You can store the file locally and specify it as file:/

About the Author

Roman Melnikov

Roman Melnikov

Technical Writer and System Administrator

Work Experience: Technical writer and DevOps engineer with 9 years of experience. Created over 50 detailed guides on system configuration and administration. His instructions helped thousands of professionals successfully solve technical tasks. Popular author on Habr and YouTube.
Education: Bauman Moscow State Technical University. Information Systems and Technologies
Expertise:
Technical Documentation DevOps System Administration Linux Docker and Kubernetes CI/CD Infrastructure Automation Cloud Technologies System Monitoring Bash and Python Scripting

Share this article: