HTTP proxies are the most common type most people encounter — often built into a browser's own settings — and understanding how they handle plain HTTP versus HTTPS traffic differently clarifies exactly what visibility they actually have.

How plain HTTP forwarding works

For an unencrypted HTTP request, the proxy receives your full request — including the URL and any data — and forwards it to the destination on your behalf, relaying the response back. Because this traffic is unencrypted, the proxy can see and technically modify everything passing through it.

How HTTPS is handled differently: the CONNECT method

For HTTPS traffic, an HTTP proxy generally can't simply forward and read the request, because the destination site's TLS certificate is bound to the site's own domain, not the proxy's. Instead, browsers use the CONNECT method: the browser asks the proxy to open a raw tunnel to the destination, then performs the actual TLS handshake directly with the destination through that tunnel. The proxy relays encrypted bytes without being able to read them — it knows which destination you connected to, but not the content of the encrypted session.

What each party can actually observe

  • For HTTP: the proxy sees everything — full request and response content.
  • For HTTPS via CONNECT: the proxy sees the destination host and port, but not the encrypted content itself — assuming it isn't performing TLS interception (some corporate/enterprise proxies deliberately install their own certificate to do exactly this, which is a different, more invasive setup worth being aware of separately).

FAQ

Does an HTTP proxy encrypt my traffic?

No — by itself an HTTP proxy provides no encryption of its own. For HTTP sites, your traffic is exactly as visible to the proxy as it would be to your ISP without a proxy at all.

Is an HTTP proxy the same as a VPN?

No — see Proxy vs VPN for the broader comparison; an HTTP proxy specifically only handles web traffic, not your device's full network connection.