Cannot connect or resolve host
Confirm the allocated host and port, local DNS, firewall and protocol. The public proxy.example.invalid placeholder is intentionally non-resolving. A timeout before a connection differs from a slow target response. Set bounded connection and total timeouts; avoid infinite retry loops.
407: proxy authentication required
Check that the service is active, that the right credential is selected and that the client sends authentication to the proxy. A CloudCity account password or management API key is not a proxy password. Check URL encoding if credentials contain special characters. Do not send secrets in a support ticket.
403, 429 and 5xx responses
Determine whether the response came from the target or intermediary using safe metadata. A 403 can indicate policy denial; do not treat it as permission to bypass controls. For 429 honor Retry-After where present and reduce request rate. Retry transient 5xx only within a small budget and only when the operation is safe to repeat.
TLS and unexpected content
Verify hostname, certificate chain and clock. Do not disable certificate validation. HTTP 200 can still be a login page, challenge or wrong locale, so assert expected content. Preserve a sanitized status, stage, timestamp and request identifier; redact authorization headers, cookies and response data before sharing diagnostics.