Fastest diagnosis

Switch to Direct first. If Direct also fails, fix the base network. If Direct works but the proxy fails, verify protocol, host, port, and authorization. If the profile looks active but the exit IP does not change, check bypass rules, System mode, competing extensions, and enterprise policy.

Classify the symptom

SymptomCheck first
Every page times outEndpoint availability, protocol and port, outbound network access
407 or a credential promptCredentials, IP allowlist, authentication host and port
Exit IP does not changeActive profile, matching bypass rule, or System mode
Settings revert automaticallyAnother proxy extension, Chrome enterprise policy, or managed software

Six diagnostic layers

  1. Base network: switch to Direct and open two unrelated sites. Do not keep changing proxy settings if the base connection is down.
  2. Endpoint: copy the host and port again from the provider dashboard. Confirm the plan is active and accepts your current network.
  3. Protocol: HTTP, HTTPS, SOCKS4, and SOCKS5 are not interchangeable labels. Select the type supplied by the provider.
  4. Authentication: for 407, use the proxy authentication checklist.
  5. Routing: temporarily clear profile and global bypass rules to rule out a direct route for the target.
  6. Control: leave one proxy extension enabled at chrome://extensions and inspect enforced settings at chrome://policy.

Direct, System, and a custom proxy

Direct is the no-extension-proxy baseline. System makes Chrome follow operating-system settings; the extension does not choose the endpoint. ProxyFox applies an endpoint only when an HTTP, HTTPS, or SOCKS profile is active. Do not confuse selecting a profile with proving the endpoint is reachable.

Use the connection test correctly

ProxyFox's pre-save test temporarily applies a candidate, visits your configured test URL, records apply and network timing, and restores the previous state. Success proves that the endpoint completed that request at that moment. It does not guarantee access to every site or monitor proxy health continuously.

A certificate error is not evidence that the proxy failed to apply.A proxy or enterprise gateway may be inspecting TLS. Ask an administrator to deploy a trusted certificate instead of bypassing Chrome warnings.

Collect evidence before asking for help

  • Chrome version and operating system;
  • proxy protocol, redacted host, and port;
  • whether Direct works;
  • the exact code, such as ERR_PROXY_CONNECTION_FAILED, ERR_TUNNEL_CONNECTION_FAILED, or 407;
  • enterprise policy and other proxy extensions;
  • the failed test stage and timing—not passwords or a full exported profile.

If the issue remains, file redacted details in GitHub Issues.