How to open, view and edit a .pac file

Published

A .pac file (proxy.pac or wpad.dat) is plain JavaScript text. You do not need special software to open it. The hard parts are finding which file your computer actually uses, and changing it without breaking routing for everyone.

Commands marked (expert) are practitioner knowledge that has not been verified in our lab yet.

1. Find the PAC URL in use

A client either has the PAC URL configured, or finds it through WPAD. To see the configured URL:

WhereHow
Windows (user setting)reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v AutoConfigURL (expert)
macOSscutil --proxy, look for ProxyAutoConfigURLString (expert)
GNOME desktopgsettings get org.gnome.system.proxy autoconfig-url (expert)
Chrome / Edgechrome://net-internals/#proxy shows the effective settings (expert)
FirefoxSettings → Network Settings → “Automatic proxy configuration URL” (expert)

If nothing is configured but “automatically detect settings” is on, the client is using WPAD, and the file is usually http://wpad.<your domain>/wpad.dat.

2. Download it

curl -sS -D - -o proxy.pac https://pac.corp.example/proxy.pac

-D - prints the response headers. Keep them, because they show how the file is delivered. A Content-Type of application/x-ns-proxy-autoconfig and an explicit Cache-Control: max-age are what you want (PAC-D002, PAC-D003). The tester grades pasted headers too.

3. Open and view it

Any text editor works. Use one with JavaScript syntax highlighting and line numbers, because PAC findings and browser logs refer to line numbers. You can also view it online. Paste it into the PAC file tester or load it with Load file…, and the editor shows line numbers. Press Check to see where each test URL goes.

Things to read first:

  • the last statement of FindProxyForURL. It should be an unconditional return with a comment, because it decides every request nothing else matched (PAC-X001, PAC-B004);
  • every DIRECT, since each one is an exception to your proxy policy;
  • any dnsResolve, isResolvable or isInNet(host, …). These are DNS lookups on every request (DNS in PAC files).

4. Edit it safely

  • Keep it ES5 if Windows services or other WinHTTP clients use the file. let, const, arrow functions and template strings break older engines. The tester’s “Target WinHTTP / ES5 engines” setting flags them.
  • Use the leading dot: dnsDomainIs(host, ".corp.example"), not "corp.example" (PAC-X003).
  • Test host, not url (PAC-C001).
  • Use braces on every if, so the next edit cannot change the logic by accident (PAC-B001).
  • Version it. Keep the file in version control with a list of test URLs and their expected answers, and run pactester or the online tester before each deployment (how to test a PAC file).
  • Roll out with a short cache. Lower max-age before a change so a mistake can be undone quickly.

Starting over is often easier than editing a file that has grown for years. The PAC file generator writes a clean, commented file from your list of proxies, direct domains and networks.

Frequently asked questions

What program opens a .pac file?

Any text editor, such as Notepad, TextEdit, VS Code or vim. A .pac file is JavaScript source.

How do I view a PAC file online?

Open findproxyforurl.net/check/ and paste the file or load it with "Load file…". The editor shows it with line numbers, and Check tests it. The file is evaluated in your browser and is not stored.

Where do I find the PAC file my computer uses?

On Windows, the AutoConfigURL value under the user's Internet Settings registry key. On macOS, scutil --proxy. In Chrome, chrome://net-internals/#proxy. Then download that URL with curl.