PAC-C027 · cloudflare-gateway-endpoint-needs-https-keyword

Cloudflare Gateway proxy endpoint with PROXY instead of HTTPS

high · Correctness

Cloudflare Gateway proxy endpoints only accept TLS from the browser. The PAC must return "HTTPS <subdomain>.proxy.cloudflare-gateway.com:443"; "PROXY ..." to the same host fails for every request and the browser falls through to the next entry or to an error.

Why it matters

Cloudflare’s PAC best practices spell this out as the first formatting rule: “Make sure the directive used for the endpoint is HTTPS and not PROXY”, with return "HTTPS your-subdomain.proxy.cloudflare-gateway.com:443"; as the correct and the PROXY form as the incorrect example. HTTPS host:port means the hop from browser to proxy is TLS; PROXY host:port means plain HTTP CONNECT. The endpoint has no plain-HTTP listener, so the PROXY form is a connection that never completes. This is specific to TLS-terminating gateways. For a typical on-premises forward proxy the opposite holds (see PAC-K006), which is why the checker only applies this rule when the Cloudflare pack is selected and the host is a proxy.cloudflare-gateway.com name.

How to fix

Change the keyword to HTTPS and keep port 443, e.g. return "HTTPS abc123def0.proxy.cloudflare-gateway.com:443";

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY abc123def0.proxy.cloudflare-gateway.com:443";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "HTTPS abc123def0.proxy.cloudflare-gateway.com:443";
}
Open good example in checker

Cloudflare pack only; the subdomain in the examples is synthetic.

Engine behaviour

EngineBehaviourSource
chromium"HTTPS host:port" opens TLS to the proxy; accepted PAC keyword.doc, verified 2026-10-04 · ref
firefoxSupports the HTTPS proxy type through a PAC file (Cloudflare lists Firefox as supported).doc, verified 2026-10-04 · ref
macos-cfnetworkSafari and iOS/iPadOS do not support the HTTPS proxy type required by proxy endpoints.doc, verified 2026-10-04 · ref

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References