What is a PAC file? proxy.pac and wpad.dat explained

Published

A PAC file (proxy auto-configuration file) is a small JavaScript program that a browser asks, for every request, "which proxy should I use for this URL?". It answers DIRECT or a list of proxies. proxy.pac and wpad.dat are the two usual names for the same kind of file.

How a PAC file works

A PAC file defines one function, FindProxyForURL(url, host). The browser downloads the file once, keeps it, and calls the function before every connection:

function FindProxyForURL(url, host) {
  host = host.toLowerCase();
  // internal names and domains go direct
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  // default route: always the last statement
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
  • url is the requested URL and host its host name.
  • The return value is a string. DIRECT means no proxy. PROXY host:port names an HTTP proxy. Several entries separated by semicolons are tried in order.
  • The file can call a small set of helper functions such as dnsDomainIs, shExpMatch, isPlainHostName and isInNet. It cannot read files or make web requests.

The format dates back to Netscape Navigator in the 1990s. MDN documents the current browser behaviour (MDN, doc, checked 2026-10-06).

How clients find the file

  1. Configured explicitly: an administrator sets the PAC URL through group policy, MDM or the operating system’s proxy settings, for example https://pac.corp.example/proxy.pac. This is the recommended way.
  2. Discovered through WPAD: with “automatically detect settings”, clients ask DHCP or DNS for a host called wpad and fetch http://wpad.<domain>/wpad.dat. It is convenient, and it is risky. See WPAD and wpad.dat.

Serve the file as application/x-ns-proxy-autoconfig, over HTTPS, with a Cache-Control: max-age of at most a day (PAC-D001, PAC-D002, PAC-D003).

Why PAC files go wrong quietly

A broken PAC rarely produces an error a user would see. Chromium and Firefox connect directly when the function throws or returns nothing (source: code, verified 2026-10-04; see the engine differences). So most PAC mistakes end in one of two ways. Traffic silently bypasses the proxy, or every request waits for DNS. Common examples:

  • a missing final return (PAC-X001);
  • dnsDomainIs(host, "corp.example") without the leading dot, which also matches evilcorp.example (PAC-X003);
  • testing url instead of host (PAC-C001);
  • isInNet(host, …) on a host name, which costs a DNS lookup on every request (PAC-P002, and see DNS in PAC files).

The 20 most dangerous PAC mistakes lists the rest in order.

Browsers do not agree

The same file can give different answers in different engines. Chrome removes the path and query of https:// URLs before calling the function. Firefox removes them for every scheme, and pactester (pacparser) passes the URL unchanged (source: code, verified 2026-10-04). Only some engines have the Microsoft IPv6 functions such as isInNetEx. Test a PAC in more than one engine, which is what the online PAC file tester does.

Frequently asked questions

What is a PAC file used for?

To route web traffic per destination. Typical PAC files send internal sites and private address ranges direct and everything else through a corporate or cloud proxy, with a second proxy as fallback.

What is the difference between proxy.pac and wpad.dat?

None in content. Both are PAC files that define FindProxyForURL. wpad.dat is the name that WPAD auto-discovery requests; proxy.pac is the usual name when the file's URL is configured explicitly.

Is a PAC file a security control?

No. It decides routing and can be bypassed by any user or program that ignores it. Enforce policy at the egress firewall and treat the PAC as a convenience that must fail safely.

How do I check a PAC file?

Paste it into the online PAC file tester at findproxyforurl.net/check/. It runs the file in Chromium, Firefox and pacparser engine profiles and lists every finding with a fix.