Skip to content
Let’s plan the right software for your processes. Call us for a demo or a quote: +90 546 737 48 29

TR EN DE

What is a proxy server?

A proxy server is a server that steps into the communication between two computers and forwards the request on behalf of one of them. An everyday comparison: instead of doing something yourself, you have a representative do it for you; the other party deals with your representative, not with you.

When the word "proxy" is used on its own, it usually means a forward proxy, which sits in front of the client. The kind that sits in front of websites is called a reverse proxy. Both use the same technique but serve different sides. This guide helps you tell the two apart and explains where forward proxies are used, how they differ from a VPN and what to keep in mind about privacy.

In brief

  • A proxy server is an intermediary that stands between two parties and forwards requests on behalf of one of them.
  • A forward proxy acts for the client, a reverse proxy for the server.
  • A proxy usually works at application level; a VPN carries the network traffic of the device through a tunnel.
  • Whoever runs the proxy can see the traffic; https protects the content but does not hide the destination domain.

Note

This guide explains the concepts. It does not describe ways of getting round the access rules of an organisation or a network.

On this page

Basic concepts

  1. The difference between a forward proxy and a reverse proxy

    The difference lies in on whose behalf the proxy acts:

    • Forward proxy: It goes out to the internet on behalf of the client (the browser, the computer). The client sends its request to the proxy, the proxy connects to the destination site and brings back the response. The destination site sees the proxy, not the client.
    • Reverse proxy: It receives requests on behalf of the server. The visitor believes they are connecting to your domain; in fact they have connected to the reverse proxy, which passes the request on to the application server behind it. The visitor does not see the servers at the back.
    AspectForward proxyReverse proxy
    On whose behalf does it act?The clientThe server
    Where does it sit?In front of the clients; at the exit of a company or home networkIn front of the servers; at the entry point of the site
    Who configures it?The client side: the user or the organisation's network administratorThe server side: the site owner or the system administrator
    Is the client aware of it?Usually yes; the setting is made on the client (except for a transparent proxy)No; it is invisible to the visitor
    What does the other party see?The destination site sees the IP address of the proxyThe visitor sees the address of the reverse proxy, not the backend servers
    Typical useCompany network exit, content filtering, caching, loggingTLS termination, load balancing, caching, protecting the backend
    Diagram: a forward proxy goes out to the internet on behalf of clients; a reverse proxy receives visitors' requests on behalf of the server and passes them to the backend servers : Enlarge
  2. Where are forward proxies used?

    You are most likely to meet a forward proxy on shared networks such as those of companies and schools. The computers on the network reach the internet through the proxy rather than directly, so outgoing traffic is gathered at a single point.

    • Company network exit: Direct internet connections from devices on the internal network are blocked; only the proxy can go out. Firewall rules become simpler, and from the outside a single exit address is visible.
    • Content filtering: Certain addresses or categories are blocked according to the organisation's policy; access to addresses known to be harmful is stopped.
    • Caching: Frequently requested files are stored on the proxy and served without being downloaded again. Because most web traffic is now encrypted, this use is more limited than it used to be; it is still helpful in areas such as software updates and package repositories.
    • Logging: Which device connected to which address, and when, is recorded. These records are used when investigating security incidents and where regulations require them.
    Cards: uses of a forward proxy; network exit, content filtering, caching and logging : Enlarge
  3. A proxy and a VPN are not the same thing

    In both cases traffic passes through an intermediary, which is why they are often confused. The basic difference is the layer they work at and their scope:

    • A proxy usually works at application or protocol level. Only the traffic of the application that has been configured to use the proxy passes through it. The connection to the proxy is not encrypted by itself; encryption depends on the protocol in use.
    • A VPN (virtual private network) works at network level: it carries the network traffic of the device through an encrypted tunnel set up between the device and the VPN server. Its typical use is to let someone working remotely connect securely to the company network.

    Neither provides "invisibility": the traffic still passes through the operator at the end of the tunnel or the proxy.

    Comparison: a proxy works at application or protocol level; a VPN carries the network traffic of the device through an encrypted tunnel : Enlarge
  4. How much of your traffic does a proxy see?

    A proxy server is in the middle of the path; whoever runs it can see the connections that pass through. How much they see depends on whether the connection is encrypted:

    • http:// (unencrypted): Everything, including the address, the page content and what you type into forms, can be read and altered.
    • https:// (encrypted): The content stays encrypted end to end between the browser and the site. The proxy can still see which domain you connect to, the time of the connection and the amount of data transferred.

    There is one exception: organisations can also inspect https traffic by installing an inspection certificate on the devices they manage. This is a known and legitimate practice on company devices; do not install a certificate of unknown origin on your personal device.

    Table: on an http connection the proxy operator sees everything; on an https connection only the destination domain, the time and the data volume : Enlarge

How does a proxy server work?

On a connection without a proxy, your browser connects straight to the site and the site sees your IP address. With a forward proxy the sequence is as follows:

  1. The browser sends the request to the proxy server, not to the destination site.
  2. The proxy checks its rules: is this address allowed, and is the response already in the cache?
  3. If it is allowed, the proxy connects to the destination site in its own name and receives the response.
  4. It passes the response to the browser and, where appropriate, writes it to the cache and the log.

With encrypted (https) sites the proxy cannot read the content; the browser asks the proxy to open a tunnel to the destination server and the encrypted data flows through that tunnel. The proxy only knows where the tunnel leads.

There are two common types: the HTTP proxy, which only understands web traffic, and the more general-purpose SOCKS proxy, which can relay the connections of different protocols. The type most often found on company networks is the HTTP proxy.

A brief look at the reverse proxy

A reverse proxy does the same intermediary job on the server side. When visitors connect to your domain, the reverse proxy receives the request and passes it to the application server behind it. It gives the site owner the following:

  • the certificate managed in one place (TLS termination),
  • requests spread across several servers (load balancing),
  • stored responses served from the cache,
  • backend servers that are not exposed directly to the internet.

If you publish a website or an application, this is the type that really concerns you. For the details, see the reverse proxy guide. Content delivery networks are the same idea spread around the world; the CDN guide explains this.

Transparent proxy

With an ordinary forward proxy, the client is told the address of the proxy: it is entered in the browser or operating system settings and, in organisations, is usually rolled out centrally. With a transparent proxy there is no setting on the client at all. The network gateway redirects outgoing web traffic to the proxy by itself; the user may not notice that there is a proxy in between.

Transparent proxies are used on company networks and at some internet access points for filtering, caching and logging. They are easy to manage because devices do not have to be configured one by one. With https traffic a transparent proxy cannot see the content either; it can only see the domain being connected to.

Privacy: a proxy does not make you invisible

Using a proxy server does not remove the need for trust; it only moves it. The destination site sees the address of the proxy instead of yours, but now the party running the proxy sees your traffic.

  • The operator can see and record the traffic. On unencrypted connections the content; on encrypted connections at least the domains you connect to and when.
  • Proxies of unknown ownership are risky. You cannot know who runs the servers on the "free proxy" lists that circulate on the internet, or for what purpose; unencrypted content can be altered and session details can be captured.
  • A proxy does not guarantee that your identity is hidden. Proxies may add headers to the request that carry the original client address; besides, sites already recognise you through cookies and the accounts you are signed in to.
  • Use https. With or without a proxy, the address of every page where you enter a password or personal data should begin with https. For the details, see the SSL guide.

If you are on a company network, the proxy settings are decided by your organisation's IT department; do not change them, and contact that department if you have access problems.

Which one do you need?

NeedSuitable solution
Controlling, filtering and recording internet access from the company networkForward proxy
Publishing your website or application, managing the certificate in one place, spreading the loadReverse proxy
Secure access to the company network for remote workersVPN
Serving your site from points closer to visitorsCDN

These solutions do not replace one another; in the same organisation they are often used together. One of the most common tools on the web server side is Nginx; you can find out what it is in the Nginx guide.

Frequently asked questions

What is the difference between a proxy and a reverse proxy?

A forward proxy goes out to the internet on behalf of the client and is set up on the client side; the destination site sees the proxy. A reverse proxy receives requests on behalf of the server and is set up on the server side; the visitor does not see the servers behind it.

Am I anonymous on the internet when I use a proxy?

No. The destination site sees the address of the proxy, but whoever runs the proxy sees your traffic. Sites also continue to recognise you through cookies and the accounts you are signed in to.

Can a proxy server see my password on https sites?

Not in the normal case; https content is encrypted between the browser and the site, and the proxy only sees the domain you connect to. If an inspection certificate is installed on devices managed by an organisation, https traffic can be inspected as well.

Should I use a proxy or a VPN?

It depends on the purpose. A forward proxy is used to control the exit of a company network, a VPN to connect to the company network remotely. On company networks the IT department decides which one is used.

How can I tell whether a transparent proxy is in use?

Most of the time you cannot; there is no setting on the client. On company or shared networks, assume that traffic may pass through a proxy and, for sensitive tasks, check that the address begins with https and that the browser shows no certificate warning.

BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.

Related guides

Let us talk about your website infrastructure

BYK Yazılım builds corporate websites. Write to us with any questions about your site.

Contact us Our corporate website service