Site map
Every page on this site, grouped by section. Search engines get the same list as sitemap.xml.
Tools
Reference and guides
Articles
- Testing PAC files in CI with pactester
- Netskope and Cloudflare Gateway PAC files: the checks that matter
- IPv6 in PAC files: isInNet, isInNetEx and what actually works
- wpad.dat vs proxy.pac: same file, different delivery
- FindProxyForURL.com (2007–2024): the PAC and WPAD resource, remembered
- Online PAC file testers compared: what to look for (2026)
- Zscaler PAC file checklist: gateways, ports, variables and Client Connector
- DNS in PAC files: why isInNet and dnsResolve slow every request
- Debugging a PAC file in Chrome, Edge and Firefox
- How to open, view and edit a .pac file
- How to test a PAC file (online, with pactester, and in the browser)
- What is a PAC file? proxy.pac and wpad.dat explained
PAC functions
Engines
Rule catalogue (116)
Errors and robustness
- PAC file does not parse PAC-E001
- No FindProxyForURL function PAC-E002
- FindProxyForURL declared more than once PAC-E003
- FindProxyForURL does not take exactly two parameters PAC-E004
- Call to a function that is not defined PAC-E005
- Evaluation throws an exception PAC-E006
- Evaluation did not finish within the time limit PAC-E007
- Loop without a reachable exit PAC-E008
- Assignment used as a condition PAC-E009
- isInNet called with an invalid address, mask or argument count PAC-E010
- Return value is not a valid proxy string PAC-E011
- Proxy port out of range or not numeric PAC-E012
- File starts with a UTF-8 byte order mark PAC-E013
- Non-ASCII characters in code PAC-E014
- Zero-width or bidirectional control characters PAC-E015
- Statements after an unconditional return PAC-E016
- PAC helper called with the wrong number of arguments PAC-E017
- console.log or other browser APIs used in the PAC PAC-E018
- Unknown Zscaler PAC variable PAC-E019
Security and fail-safety
- No unconditional return at the end of FindProxyForURL PAC-X001
- Trailing * in a host pattern matches attacker-controlled suffixes PAC-X002
- dnsDomainIs pattern without a leading dot matches look-alike domains PAC-X003
- Leading * without a dot matches look-alike domains PAC-X004
- Pattern matches an entire top-level domain PAC-X005
- IP range matched as a text prefix PAC-X006
- String prefix used to match an IP range PAC-X007
- Port matched as a substring of the URL PAC-X008
- Pattern with leading and trailing * is a substring match PAC-X009
- dnsResolve result compared with a literal address PAC-X010
- Exceptions are caught and turned into DIRECT PAC-X011
- Wildcard inside a domain label PAC-X012
- PROXY entry without a port PAC-X013
- DIRECT as fallback after a proxy PAC-X014
- eval or Function constructor in the PAC PAC-X015
Correctness
- Hostname pattern applied to url instead of host PAC-C001
- URL scheme in a host pattern PAC-C002
- Path, port or query characters in a host pattern PAC-C003
- Wildcard characters in dnsDomainIs or localHostOrDomainIs PAC-C004
- isPlainHostName called with url PAC-C005
- Bitwise | or & used instead of || or && PAC-C006
- RFC 1918 range with the wrong mask PAC-C007
- Only 127.0.0.1 excluded instead of 127.0.0.0/8 PAC-C008
- Domain matched exactly, subdomains not covered PAC-C009
- dnsDomainLevels used without excluding IP literals PAC-C010
- Very short or trailing-dot dnsDomainIs pattern PAC-C011
- IPv4 loopback/private ranges handled, IPv6 equivalents not PAC-C012
- Identical condition appears twice PAC-C013
- Branch can never match because an earlier branch covers it PAC-C014
- URL pattern pinned to http:// only PAC-C015
- isInNet arguments in the wrong order PAC-C016
- Condition is a constant PAC-C017
- Upper-case letters in a hostname pattern PAC-C018
- Zscaler gateway on an undocumented port PAC-C019
- Forwarding Profile and App Profile roles mixed in one Zscaler Client Connector PAC PAC-C020
- Netskope explicit proxy on the wrong port PAC-C021
- Identity provider not excluded from the SSE proxy PAC-C022
- Non-HTTP URLs reach a proxy that only accepts HTTP and HTTPS PAC-C023
- Skyhigh cloud proxy on a port browsers cannot use PAC-C024
- Secure Web Gateway itself is not returned DIRECT PAC-C025
- Plain hostnames or private addresses are sent to the cloud proxy PAC-C026
- Cloudflare Gateway proxy endpoint with PROXY instead of HTTPS PAC-C027
- Cloudflare Gateway proxy endpoint on a port other than 443 PAC-C028
- Prisma Access Explicit Proxy on a port other than 8080 PAC-C029
- Prisma Access service domains not returned DIRECT PAC-C030
Compatibility across engines
- ES2015+ syntax (let, const, arrow functions, template literals) PAC-K001
- alert() used in the PAC PAC-K002
- IPv6 extension functions (isInNetEx, dnsResolveEx, myIpAddressEx) PAC-K003
- FindProxyForURLEx entry point PAC-K004
- SOCKS keywords mean different versions on different engines PAC-K005
- HTTPS proxy keyword without a PROXY fallback PAC-K006
- Time-based routing (weekdayRange, dateRange, timeRange) PAC-K007
- Mutable state outside FindProxyForURL PAC-K008
- Case-sensitive host comparisons without lower-casing host PAC-K009
- ES2015+ library methods (includes, startsWith, Map, Set) PAC-K010
- Routing depends on Math.random or the clock PAC-K011
- Engines return different results for the same URL PAC-K012
- Routing decided by myIpAddress() PAC-K013
- isInNet called with an IPv6 address PAC-K014
- Regular-expression syntax inside a shExpMatch pattern PAC-K015
- Zscaler gateway named directly instead of through ${GATEWAY} PAC-K016
- ES2015+ syntax and the Zscaler Client Connector legacy PAC parser PAC-K017
- Legacy Skyhigh / McAfee cloud proxy domain PAC-K018
- IPv6 address in a PROXY statement for Prisma Access PAC-K019
Performance
- DNS lookup on every request PAC-P001
- isInNet called with a hostname PAC-P002
- isResolvable used as a reachability test PAC-P003
- dnsResolve called repeatedly for the same host PAC-P004
- DNS-dependent rule placed before string rules PAC-P005
- PAC file is large PAC-P006
- Many conditions and branches PAC-P007
- Deeply nested conditions PAC-P008
Best practice and maintainability
- if statement without braces PAC-B001
- Parameters not named url and host PAC-B002
- Unused functions or variables PAC-B003
- Default route has no comment PAC-B004
- Same proxy string repeated many times PAC-B005
- isPlainHostName alone sends every single-label name direct PAC-B006
- *.local routed direct PAC-B007
- Long list of public hostnames routed around the proxy PAC-B008
- Result assembled in a variable instead of returned per rule PAC-B009
- Empty block PAC-B010
- Single proxy without a fallback entry PAC-B011
- Single Zscaler gateway without ${SECONDARY_GATEWAY} PAC-B012
- PAC sends traffic to a proxy the Netskope Client may not know PAC-B013
- DIRECT in the PAC does not bypass the vendor's agent PAC-B014
- Selected vendor pack, but the PAC never routes to that vendor PAC-B015
Delivery (HTTP headers)
- PAC served over plain HTTP PAC-D001
- Content-Type is not application/x-ns-proxy-autoconfig PAC-D002
- No Cache-Control header on the PAC response PAC-D003
- PAC marked no-cache / no-store / max-age=0 PAC-D004
- PAC cached for more than a day PAC-D005
- Large PAC served without compression PAC-D006
- PAC distributed via WPAD DNS discovery PAC-D007
- PAC URL distributed via DHCP option 252 PAC-D008
- PAC loaded from a file path or SMB share PAC-D009
- PAC URL does not return 200 PAC-D010