HTTP proxy, HTTPS destination
An HTTP proxy commonly carries HTTPS through a CONNECT tunnel. Your client negotiates TLS with the target inside the tunnel. The proxy URL scheme describes the connection to the proxy, while the target URL scheme describes the destination. Do not change http:// to https:// merely because the target uses HTTPS.
TLS to the proxy
An HTTPS proxy encrypts the client-to-proxy connection when both the endpoint and client support it. It has its own certificate checks, separate from the target. Use the scheme and trust configuration documented for your allocated service. Never solve a certificate error by disabling verification globally.
SOCKS and DNS
SOCKS5 support is service- and client-specific. Libraries differ in whether DNS resolution happens locally or through the proxy; cURL distinguishes socks5 from socks5h. Do not infer SOCKS, UDP or remote DNS support from an HTTP endpoint. The public examples demonstrate HTTP syntax only.
Diagnose the correct layer
A TCP timeout, failed CONNECT, proxy authentication error, certificate failure and target HTTP response are different failures. Record the stage without credentials. Confirm host/port and client compatibility first, then inspect certificate hostname, expiry and trust chain. Contact support with a safe request identifier and timestamp.