# What is a PAC file? proxy.pac and wpad.dat explained

Source: https://findproxyforurl.net/articles/what-is-a-pac-file/ · updated 2026-10-06

A PAC file (proxy auto-configuration file) is a small JavaScript program that a browser asks, for every request, "which proxy should I use for this URL?". It answers DIRECT or a list of proxies. proxy.pac and wpad.dat are the two usual names for the same kind of file.

## How a PAC file works

A PAC file defines one function, [`FindProxyForURL(url, host)`](https://findproxyforurl.net/findproxyforurl/). The browser
downloads the file once, keeps it, and calls the function before every connection:

```js
function FindProxyForURL(url, host) {
  host = host.toLowerCase();
  // internal names and domains go direct
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  // default route: always the last statement
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
```

- `url` is the requested URL and `host` its host name.
- The return value is a string. `DIRECT` means no proxy. `PROXY host:port` names an HTTP proxy.
  Several entries separated by semicolons are tried in order.
- The file can call a small set of [helper functions](https://findproxyforurl.net/functions/) such as `dnsDomainIs`,
  `shExpMatch`, `isPlainHostName` and `isInNet`. It cannot read files or make web requests.

The format dates back to Netscape Navigator in the 1990s. MDN documents the current browser
behaviour ([MDN, doc, checked 2026-10-06](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Proxy_servers_and_tunneling/Proxy_Auto-Configuration_PAC_file)).

## How clients find the file

1. **Configured explicitly**: an administrator sets the PAC URL through group policy, MDM or the
   operating system's proxy settings, for example `https://pac.corp.example/proxy.pac`. This is
   the recommended way.
2. **Discovered through WPAD**: with "automatically detect settings", clients ask DHCP or DNS for
   a host called `wpad` and fetch `http://wpad.<domain>/wpad.dat`. It is convenient, and it is
   risky. See [WPAD and wpad.dat](https://findproxyforurl.net/wpad/).

Serve the file as `application/x-ns-proxy-autoconfig`, over HTTPS, with a `Cache-Control: max-age`
of at most a day ([PAC-D001](https://findproxyforurl.net/rules/pac-over-plain-http/), [PAC-D002](https://findproxyforurl.net/rules/wrong-content-type/),
[PAC-D003](https://findproxyforurl.net/rules/missing-cache-control/)).

## Why PAC files go wrong quietly

A broken PAC rarely produces an error a user would see. Chromium and Firefox connect **directly**
when the function throws or returns nothing (source: code, verified 2026-10-04; see the
[engine differences](https://findproxyforurl.net/engines/differences/)). So most PAC mistakes end in one of two ways. Traffic
silently bypasses the proxy, or every request waits for DNS. Common examples:

- a missing final `return` ([PAC-X001](https://findproxyforurl.net/rules/no-default-return/));
- `dnsDomainIs(host, "corp.example")` without the leading dot, which also matches
  `evilcorp.example` ([PAC-X003](https://findproxyforurl.net/rules/dnsdomainis-without-leading-dot/));
- testing `url` instead of `host` ([PAC-C001](https://findproxyforurl.net/rules/url-instead-of-host/));
- `isInNet(host, …)` on a host name, which costs a DNS lookup on every request
  ([PAC-P002](https://findproxyforurl.net/rules/isinnet-on-hostname/), and see
  [DNS in PAC files](https://findproxyforurl.net/articles/dns-in-pac-files/)).

The [20 most dangerous PAC mistakes](https://findproxyforurl.net/top-20/) lists the rest in order.

## Browsers do not agree

The same file can give different answers in different engines. Chrome removes the path and query
of `https://` URLs before calling the function. Firefox removes them for every scheme, and
`pactester` (pacparser) passes the URL unchanged (source: code, verified 2026-10-04). Only some
engines have the Microsoft IPv6 functions such as `isInNetEx`. Test a PAC in more than one engine,
which is what the [online PAC file tester](https://findproxyforurl.net/check/) does.


## Frequently asked questions

### What is a PAC file used for?

To route web traffic per destination. Typical PAC files send internal sites and private address ranges direct and everything else through a corporate or cloud proxy, with a second proxy as fallback.

### What is the difference between proxy.pac and wpad.dat?

None in content. Both are PAC files that define FindProxyForURL. wpad.dat is the name that WPAD auto-discovery requests; proxy.pac is the usual name when the file's URL is configured explicitly.

### Is a PAC file a security control?

No. It decides routing and can be bypassed by any user or program that ignores it. Enforce policy at the egress firewall and treat the PAC as a convenience that must fail safely.

### How do I check a PAC file?

Paste it into the online PAC file tester at findproxyforurl.net/check/. It runs the file in Chromium, Firefox and pacparser engine profiles and lists every finding with a fix.

