How to set up a proxy on a Mac
Open System Settings > Network, select your connection (for example Wi-Fi), click Details, then Proxies. Turn on both Web proxy (HTTP) and Secure web proxy (HTTPS), enter the same gateway IP and port in each, and click OK. Safari and Chrome use it right away.
macOS keeps proxy settings per network service. Your Wi-Fi, a USB Ethernet adapter and a Thunderbolt dock each have their own Proxies page, and the one in use is whichever service is connected right now. Safari, Chrome, Edge and most Mac apps read those settings through the system’s networking layer, so one change covers a lot of software.
The usual mistakes on a Mac: filling in only Web proxy (HTTP) so every HTTPS site skips the proxy, setting it up on Wi-Fi and then plugging into Ethernet, and expecting Terminal tools to follow along when most of them don’t.
This guide covers the System Settings route on current macOS, the older System Preferences layout, the bypass list, full control from Terminal with networksetup and scutil, Network Locations for one-click switching, and which apps follow the setting.
Which Storm plan fits
For a Mac that browses and runs a few tools through the proxy, a rotating plan of 40 threads or more on the 15-minute gateway behaves most like a normal connection; the 10-thread package is for testing. Each browser tab uses around 10 threads. If the Mac signs in to one account that should always show the same IP, use a private dedicated proxy, which also supports a username and password.
Rotating proxies (from $14/mo): 700,000+ IPs behind fixed gateway IP:PORTs. New IP on every request, or every 3 or 15 minutes. USA, EU, USA+EU or Worldwide. Unlimited bandwidth on every plan.
Get 40 threads for $39/mo See all rotating proxies plansBefore you start
- Log in to the member area and copy your gateway
IP:PORTs. They never change; the rotation happens on our side. - Add the public IP of the computer or server that will run your tool under Authorized IPs, click Save, and allow up to 15 minutes before testing. Rotating and residential proxies use IP authentication, so there is no username or password.
- Dedicated proxies work with either IP authentication or a username and password. Use user:pass if your IP changes or the tool runs on several machines.
- Count your threads: the tool’s total open connections must stay within your plan (for example 40 threads on the 40-thread plan).
Set a proxy in macOS System Settings
- Authorize the Mac’s public IP
In the member area, add the public IP your Mac uses under Authorized IPs and click Save. Allow up to 15 minutes. Rotating and residential gateways have no username or password, so this is the only login step.
- Open the Proxies page for your connection
Apple menu > System Settings > Network. Click the service you’re connected through (Wi-Fi, Ethernet, a dock adapter), click Details…, then choose Proxies in the sidebar. On macOS Monterey and earlier: System Preferences > Network, select the service, Advanced… > Proxies.
- Turn on Web proxy (HTTP)
Switch Web proxy (HTTP) on and enter the gateway IP as the server and its port. Leave Proxy server requires password off for rotating and residential gateways.
- Turn on Secure web proxy (HTTPS) too
Switch Secure web proxy (HTTPS) on and enter the same gateway and port. This is the step most people miss. Without it, HTTPS sites, which is nearly all of them, go out from your own IP. Leave SOCKS proxy off: Storm gateways are HTTP(S) only.
- Check the bypass list
Keep Exclude simple hostnames on, so local names such as a printer or NAS go direct. In Bypass proxy settings for these hosts & domains, keep the defaults (
*.local, 169.254/16) and add anything else that should skip the proxy, separated by commas. - Click OK and test
Click OK. Open Safari and visit
https://api.ipify.org: it should show a proxy IP. In Terminal,scutil --proxyshows what the system now reports to apps. - Repeat for every service you use
If the Mac moves between Wi-Fi and Ethernet, set the same proxies on both services, or the proxy disappears the moment you plug in a cable. The Terminal script below does both in one go.
Terminal: networksetup and scutil
networksetup changes the same settings as the Proxies page; it may ask for an administrator password. Service names must match -listallnetworkservices exactly, including capitals and spaces. Replace GATEWAY_IP and PORT with your gateway.
networksetup -listallnetworkservices
networksetup -getwebproxy "Wi-Fi"
networksetup -getsecurewebproxy "Wi-Fi"
networksetup -getproxybypassdomains "Wi-Fi"
scutil --proxy # what apps actually receivenetworksetup -setwebproxy "Wi-Fi" GATEWAY_IP PORT
networksetup -setsecurewebproxy "Wi-Fi" GATEWAY_IP PORT
networksetup -setproxybypassdomains "Wi-Fi" "*.local" "169.254/16" "localhost"networksetup -setwebproxystate "Wi-Fi" off
networksetup -setsecurewebproxystate "Wi-Fi" off
networksetup -setwebproxystate "Wi-Fi" on
networksetup -setsecurewebproxystate "Wi-Fi" on#!/bin/zsh
# usage: ./proxy.sh on | off
GW=GATEWAY_IP; PORT=PORT
networksetup -listallnetworkservices | tail -n +2 | grep -v '^\*' | while read -r svc; do
if [[ "${1}" == "on" ]]; then
networksetup -setwebproxy "$svc" $GW $PORT
networksetup -setsecurewebproxy "$svc" $GW $PORT
else
networksetup -setwebproxystate "$svc" off
networksetup -setsecurewebproxystate "$svc" off
fi
done
scutil --proxy | grep -E "HTTPEnable|HTTPSEnable|HTTPProxy"# test the gateway directly, whatever the system says
curl -x http://GATEWAY_IP:PORT https://api.ipify.org
# most CLI tools read these instead of System Settings
export HTTP_PROXY="http://GATEWAY_IP:PORT"
export HTTPS_PROXY="http://GATEWAY_IP:PORT"
export NO_PROXY="localhost,127.0.0.1,.local"Which Mac apps use the system proxy
- Follow it: Safari, Google Chrome, Microsoft Edge, Brave and other Chromium browsers, App Store apps that use Apple’s networking frameworks, and Python’s
requests, which reads the macOS proxy when noHTTPS_PROXYvariable is set. Electron apps (Slack, VS Code and similar) usually follow it too. - Follow it if set to: Firefox, when its Connection Settings say Use system proxy settings. Otherwise it uses its own proxy (see the Firefox guide).
- Ignore it:
curl,wget, Git, Homebrew, Node.js and most Terminal tools. Use the environment variables above or each tool’s own setting; the cURL guide has the details. - Can’t use it: games, voice and video calls and anything else that sends UDP. An HTTP(S) proxy carries TCP connections only.
For an app that ignores the proxy and has no setting of its own, Proxifier for Mac can force its connections through the gateway; see the Proxifier guide.
Network Locations: one click between proxy and direct
Instead of toggling switches, create a second Network Location. A location is a saved copy of all your network services and their settings, proxies included.
- In System Settings > Network, click the Action pop-up menu (the round “…” button) and choose Locations > Edit Locations. Click +, name it
Proxyand click Done. - Switch to it, then set the Web and Secure web proxies on each service as above.
- Switch between
Automatic(direct) andProxyfrom Apple menu > Location (it appears once you have a second location), or in Terminal withnetworksetup -switchtolocation Proxy.
That’s handy on a laptop: proxy on for a research session, off for video calls, without retyping the gateway.
Threads and gateways for a whole Mac
A system proxy carries every app that follows it: iCloud, software updates, mail, chat and your browser. The plan’s thread limit counts all of their open connections together, and one browser tab already takes around 10. If pages stall once a few apps are open, add the busy background domains to the bypass list (for example *.icloud.com, *.apple.com) or move up a package.
Gateway choice: the Main rotating gateway changes IP with each new connection, which is good for checking pages from many IPs but breaks logins and Apple ID prompts. For normal use of a proxied Mac, the 15-minute gateway is the calmest choice, the 3-minute gateway (USA only) suits registrations and social sites, and search engines belong on the Main gateway within a quarter of your threads. A residential port gives a residential IP that changes every 5 minutes at fixed times, so a long video upload or download may restart at the switch.
Password-protected proxies and the keychain
Only private dedicated proxies offer a username and password at Storm. Turn on Proxy server requires password and enter them on both the HTTP and HTTPS entries; macOS stores them in your keychain, and apps read them from there. Some apps still prompt or fail on their own, so IP authorization (also available on dedicated proxies) is the less fussy option. If your Mac’s home IP changes, authorize a free dynamic DNS hostname (No-IP or similar) so you don’t have to update the member area every time.
Common errors and fixes
curl -x to see the error directly, and check the connection failed guide.HTTP_PROXY and HTTPS_PROXY or pass -x to curl.networksetup says the service isn’t validThe name doesn’t match exactly. Copy it from networksetup -listallnetworkservices and keep the quotes, for example "USB 10/100/1000 LAN".*.local to the bypass list.FAQ
Do I need both Web proxy and Secure web proxy on a Mac?
Yes. Web proxy (HTTP) covers plain http:// addresses and Secure web proxy (HTTPS) covers https:// ones. Point both at the same gateway. The traffic to HTTPS sites stays encrypted inside the proxy tunnel.
How do I check my proxy settings on a Mac from Terminal?
Run scutil --proxy for the settings apps receive, or networksetup -getwebproxy "Wi-Fi" and -getsecurewebproxy for one service. curl -x http://GATEWAY_IP:PORT https://api.ipify.org confirms the gateway itself works.
Does the Mac proxy apply to Terminal and Homebrew?
No. Most command-line tools use the HTTP_PROXY and HTTPS_PROXY environment variables. Add the export lines to ~/.zshrc if you want them in every Terminal window.
Can I use Storm proxies on a Mac without a username and password?
Yes, and for rotating and residential plans that’s the only way: authorize your Mac’s public IP in the member area and leave Proxy server requires password off. Private dedicated proxies accept either IP authorization or user:pass.
Which Storm gateway should a proxied Mac use?
The 15-minute rotating gateway for everyday use, so logins and app sign-ins see a steady IP. Use the Main gateway for one-off checks from many IPs and for search engines (up to a quarter of your threads), and a dedicated proxy when you need the same IP every day.
Is there a SOCKS option for Storm on macOS?
No. Storm doesn’t offer SOCKS, so leave SOCKS proxy off. Storm gateways are HTTP(S) proxies and go in the Web and Secure web proxy fields.
Still have questions? Contact us here. A real person answers.
Related guides
Tool facts checked against the official documentation (October 2026): Apple: Change Proxies settings on Mac · Apple: Manage network locations on Mac. Storm Proxies facts: our plans page and refund policy.
Unlimited bandwidth. One flat monthly price.
Access is live the moment you pay, and the smallest package of each proxy type has a 24-hour money-back guarantee on your first order.