Referral Program →
HomeGlossarySSL Proxy
Glossary

SSL Proxy

A proxy that handles SSL/TLS-encrypted connections, either tunneling them intact or terminating and re-encrypting them for inspection.

An SSL proxy handles SSL/TLS-encrypted traffic - the encryption behind every https:// connection. In the common case, an SSL proxy tunnels the encrypted connection through untouched (the same behavior as an HTTPS proxy using CONNECT), so the encryption stays end-to-end between your client and the target.

A second, distinct meaning is SSL interception (or SSL termination), where the proxy decrypts traffic, inspects or modifies it, then re-encrypts it before forwarding. This is used by corporate security gateways and reverse proxies for filtering and caching, but it requires the client to trust the proxy's certificate - otherwise the browser warns of a security risk.

For proxy users doing scraping or automation, "SSL proxy" almost always means the first meaning: a proxy that correctly tunnels your HTTPS traffic without breaking encryption. The terms SSL proxy, HTTPS proxy, and HTTP proxy with CONNECT largely overlap in commercial offerings.

The key point is that a well-behaved SSL proxy does not weaken your encryption - your TLS session is negotiated directly with the target. Only intercepting proxies (which you would deliberately configure and trust) sit inside the encrypted channel.

A marketing term with two meanings

Most providers use SSL proxy to mean a proxy that supports HTTPS traffic, which today is every proxy worth buying. In that sense the term carries no information: HTTPS goes through a CONNECT tunnel and the proxy handles it without seeing the contents.

The second meaning is the technical one: a proxy that terminates TLS itself, decrypts the traffic, inspects or modifies it, and re-encrypts it towards the destination. This requires the client to trust a certificate the proxy presents, which is why it exists inside corporate networks and not as a retail product.

SSL itself has been deprecated for years. Everything in current use is TLS, and the name persists out of habit rather than accuracy.

What ours do

We tunnel HTTPS without touching it. Nothing we run terminates your TLS:

What we see and what we do not

We see     the hostname in CONNECT, timing, byte counts
We do not  the request path, headers, body, or response

curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com
  • If a provider advertises SSL inspection or content modification, that is a different product with different privacy properties. Ours is a tunnel.
  • Certificate warnings while using our proxies point at interception elsewhere on your network, or at a client configured to trust a corporate root.
  • Disabling certificate verification to make an error go away usually hides a 407 rather than solving anything.
  • The hostname is visible in the CONNECT line by design. Anyone promising otherwise for a standard HTTP proxy is describing something they do not have.

SSL proxy confusions

It does not mean more secure

Your security comes from TLS between your client and the site, which is present either way.

SSL and TLS are used interchangeably in marketing

SSL is obsolete. Everything current is TLS, whatever the product page says.

Interception is not a feature you want

In a retail proxy it would mean the operator can read your traffic.

It is not related to certificate errors you see

Those come from your client's trust store or from a middlebox on your network.

Ready to use ssl proxy?

SotaProxy gives you access to rotating residential, mobile, datacenter, and ISP proxies. No minimum commitment.

Get started