PAC file generator

Build a proxy.pac / wpad.dat for your own proxies: an ordered failover list, the hosts, domains and networks that go direct, a comment on every block and every entry. The output is ES5, avoids DNS lookups and scores A+ in the checker.

Enter your proxies in failover order and the destinations that must not use them. Every line may carry a comment after #; it ends up next to the entry in the generated file, so the next person knows why it is there. The file is built in your browser; nothing is sent anywhere until you open it in the checker.
Proxies

One per line: [PROXY|HTTPS|SOCKS5] host:port, then an optional # comment. PROXY is the default type. Clients try the entries top to bottom and move on when a proxy does not answer.

    Written above the final return statement, the line that decides every request nothing else matched.

      Lowers the grade unless "Accept fail-open" is ticked in the checker settings. A proxy.pac is for routing, not for security: with this option, clients bypass the proxy whenever it is down, so the firewall must decide whether that is allowed. See direct-fallback-in-proxy-list.

        Direct hosts and domains

        One per line. A name (wiki.partner.example) matches exactly that host; a name with a leading dot (.corp.example) matches the domain itself and every subdomain. No wildcards, no IP addresses (those go in the networks list).

            Direct networks

            IPv4 networks in CIDR notation, one per line (a bare address means /32). The network address must be aligned (10.20.0.0/16, not 10.20.1.0/16). They apply to IP-literal URLs only: the file never resolves a host name to compare it with a network, because that DNS lookup would block every request. See isinnet-on-hostname, dns-function-on-hot-path.

                Options

                Host names are case-insensitive, string comparisons are not. See host-not-lowercased.

                  Cheap and usually right inside a company network; a mistyped public name then fails locally instead of at the proxy. See plain-hostname-blanket-direct.

                    10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.0/8 and 169.254.0.0/16, for IP-literal URLs only.

                      Bypass presets

                      Identity-provider traffic that must not depend on proxy authentication (avoids sign-in loops).

                            File header

                            Optional lines at the top of the file (owner, change reference). Plain ASCII, no personal data needed.

                              Generated proxy.pac

                              Deploying it

                              Serve the file over HTTPS (or at least from a server you control) with the content type application/x-ns-proxy-autoconfig and a short cache lifetime, for example Cache-Control: max-age=3600. Name it wpad.dat only if clients discover it through WPAD; prefer a configured PAC URL (group policy, MDM) over DNS-based WPAD discovery. Test it in the checker, roll it out to a pilot group first, and keep the previous version at hand for a quick rollback.

                              What the generated file does

                              1. Lower-cases the host, so that WIKI.Corp.Example and wiki.corp.example take the same route.
                              2. Sends plain host names, your hosts and domains, and (for IP-address URLs only) private and listed networks direct, cheapest test first. Nothing in the file resolves a name, so no request waits for DNS.
                              3. Sends everything else to your proxies in the order you listed them, with a comment on the default route: the line that decides every request nothing else matched.

                              There is no DIRECT at the end of the proxy list unless you ask for it. A proxy.pac is for routing, not for security, but a silent fail-open should be a decision, not a default.

                              Using a security service edge?

                              The SSE builders produce files for Zscaler, Netskope, Skyhigh Security, Cloudflare Gateway and Prisma Access that follow each vendor’s documentation; the checker rates them with the vendor pack.