Proxies and capture routes¶
Every capture, scan, uptime check and connection test goes out through a capture route:
| Capture route | What the site sees |
|---|---|
| VisualRunner automatic — backup routing if blocked | VisualRunner's IP. If the site blocks it, the request is retried through VisualRunner's backup route (see below). |
| Your own proxy | Your proxy's IP only. Never VisualRunner's IP, never the backup route. |
| Private Runner | Your own network (Private Runner). Proxies don't apply. |
Use your own proxies to:
- See a site from another location. Add a proxy in Germany, pick it as a monitor's capture route, and its screenshots show the site as visitors there see it.
- Get through a site that blocks cloud servers, when you can't allowlist VisualRunner's IP (for example, because you don't own the site).
Which route is used¶
- A Private Runner environment always captures from the runner's network. Its environment and monitors can't choose a proxy.
- A monitor's own capture route, if it has one: one of your proxies, or VisualRunner automatic (even when the environment has a proxy).
- Otherwise the environment's capture route (its default proxy).
- Otherwise VisualRunner automatic.
The environment card and the monitor form spell out the route in use, for example "Inherited environment proxy: Berlin (configured location: DE)". Scans and uptime checks always use the environment's route.
Add a proxy¶
- Open Workspace settings → Proxies. Only owners and admins can add, edit, disable or delete proxies. Editors can pick them for environments and monitors, and never see their credentials.
- Enter a name, its location and the URL:
http://username:password@proxy-host:port
The location is a label you give it: a country, Rotating (the exit country changes between connections) or Location unknown. VisualRunner doesn't verify it.
- Click Add proxy, then Test (see below).
After saving, only host:port is shown. The URL is stored encrypted and never
shown again. To replace it, click Edit and enter the full URL again.
Test a proxy¶
Test loads a page of an environment you choose through the proxy, the same way a real capture does, with that environment's saved login and firewall verification header. It shows:
- when it ran, whether the proxy answered, and whether the page itself loaded. A block or challenge page, a login page, or a redirect to another site counts as a failure, not a healthy route.
- the exit IP and country the proxy actually used. VisualRunner asks a public IP-lookup service through the proxy, then looks up that IP's country. Only the exit IP is sent for the country lookup.
- a location mismatch warning when the observed country differs from the proxy's configured location.
The last result stays on the proxy's row.
Capture a monitor from another location¶
In the monitor form, Capture route offers:
- Inherit environment: whatever the environment uses.
- Each of your proxies, with its configured location. If it's blocked or down, your other proxies in the same country are tried automatically.
Saving tests the page through the chosen route. If that test fails (for example, the proxy is briefly down), you can Retry test or Save paused and resume the monitor later. An invalid or unsafe proxy is always refused.
One monitor per location. To watch the same page from several places, use Duplicate for another location on a monitor. It copies the monitor's settings and asks for a different capture route. Monitors of the same page and environment show "Also monitored via …" to link them.
Baselines and route changes¶
Screenshots are only compared with screenshots taken through the same route.
- Changing the route restarts the rolling baseline. The next capture becomes the new reference, labelled "New baseline after capture route changed". This happens when:
- a monitor's capture route changes;
- an environment's route changes, for monitors that inherit it;
- a monitor moves to an environment with a different route;
- a proxy's URL is replaced.
- Renaming a proxy or changing its location label changes nothing.
- A capture already running on the old route when the route changes is never used as a baseline.
- A pinned baseline (fixed capture or saved baseline) stays as you set it. If it was captured through a different route, the monitor warns you and doesn't alert until you choose Keep comparing or Start a new baseline.
- When VisualRunner automatic has to use the backup route, the capture is labelled "VisualRunner backup route". It is compared, but it doesn't send a change alert or replace the baseline, because the difference may be the route rather than the site.
- A blocked or challenge page, or an unexpected login page, is never used as a baseline.
Capture history shows the route each screenshot actually used: VisualRunner
direct, VisualRunner backup route, Customer proxy · Berlin · configured
location: DE or Private Runner.
Disable a proxy¶
Disable stops every environment and monitor using the proxy straight away, and first shows which ones they are. Their captures, scans and uptime checks fail with "Capture route unavailable" until you enable the proxy again or pick another route. They never fall back to VisualRunner's IP. Uptime checks show "Capture route unavailable — site status unknown", not "down", and send no down alert. Settings are kept, so enabling the proxy again restores everything.
A proxy can't be deleted while an environment or monitor still uses it.
Every change to proxies is recorded in the workspace audit trail: added, edited, URL replaced, disabled, enabled and deleted. Credentials are never recorded.
What happens if the proxy is blocked or fails¶
If the site blocks your proxy, or the proxy is down, VisualRunner automatically tries your workspace's other enabled proxies with the same country (up to 3, oldest first). It never switches to a different country, VisualRunner's own IP, or the backup route.
- A capture taken through a fallback proxy compares against the same baseline as usual. Its capture history shows which proxy was used, for example "Customer proxy · Munich · configured location: DE (fallback: "Berlin" was blocked)".
- To get automatic failover, add more than one proxy with the same country. Proxies with no country set have no fallback.
- If every same-country proxy fails, the capture fails with "Capture route
unavailable". If they're all blocked, the blocked page is kept and is never
used as a baseline. The message is the same whatever the reason. Check the
proxy's address, port and login, and that it can reach the site (the
curltest below helps).
The Test button always tests only the proxy you're testing, with no fallback.
Security and privacy¶
- HTTP proxies only (
http://). The connection to the proxy isn't encrypted, so the proxy's username and password travel unencrypted between VisualRunner and the proxy. Use credentials that only work for this proxy. HTTPS sites stay encrypted end to end through it. SOCKS5 andhttps://proxy URLs aren't supported. - The proxy provider sees which sites and pages you capture. For HTTPS
sites it can't read the pages. For plain
http://pages it could, so saved logins, cookies and custom headers are never sent to anhttp://page through a proxy. This covers redirects too: if an HTTPS page redirects tohttp://, that request is refused. - The proxy must be on a public address. It is checked when you save it and again before every use. These addresses are refused:
- private, local, link-local, carrier-grade NAT, multicast and reserved addresses;
- IPv6 addresses;
- cloud metadata addresses;
- VisualRunner's own addresses.
- The port must be 80, 443, or 1024 and up, except the ports of databases and other non-web services (for example 3306, 5432, 6379).
- Limits: each workspace can change proxy URLs up to 10 times an hour and run up to 20 tests an hour through a proxy. There are also per-person and service-wide limits.
VisualRunner's backup route¶
VisualRunner keeps a pool of backup proxies, run by a third-party provider. If a site blocks VisualRunner's IP, the request is retried through the pool until one proxy gets through, up to 10 attempts. That proxy is then kept for the site. The pool only exists to get past blocks and uses whichever country works, so use your own proxy when the location matters. Routes through your own proxies never use the pool.
Turn it off if your data-routing rules don't allow a third party in the path:
- for the whole workspace, in Settings → Proxies;
- or per environment, with Use VisualRunner's backup route if blocked on the environment card.
Blocked requests then fail with a "blocked" message.
Backup route allowance¶
Each workspace gets a limited amount of the backup route:
| Plan | Allowance |
|---|---|
| Trial | 0.5 GB for the whole trial |
| Solo | 2 GB per month |
| Team | 5 GB per month |
| Business | 15 GB per month |
A full-page capture uses about 3 MB, and an uptime check far less. The environment card shows how much is used, when it resets, and how many monitors needed it this period. Owners and admins get an email at 80% and again when it's used up. After that, until it resets, captures still go direct from VisualRunner's IP. Only requests the site blocks fail, with a message saying the allowance is used up.
To stop needing it, allowlist VisualRunner's IP or generate a Firewall verification header on the environment and allow requests that carry it. Traffic through your own proxies doesn't count against the allowance.
A 403 isn't permission. The backup route gets past blanket blocks on cloud servers for sites you're authorized to monitor. It doesn't bypass logins or access controls. Only monitor sites you own or have permission to monitor.
Where to get a proxy¶
Any provider that gives you an HTTP proxy with a username and password works. For capturing from a location, pick a proxy located there, then run Test to confirm where it actually exits. A static (dedicated) IP is best, because you get the same address every time. A few providers, for reference only (VisualRunner isn't affiliated with any of them, and prices change):
| Provider | Notes |
|---|---|
| Webshare | Free plan with a few proxies, good for a first test. Cheap static residential and ISP IPs. |
| IPRoyal | Static residential IPs; you can choose the country. |
| Proxy-Cheap | Static residential and ISP IPs, priced per IP. |
| Bright Data | Premium static ISP and residential proxies. |
| Oxylabs | Premium dedicated ISP proxies. |
You can also run your own: rent a small server in the country you need and install an HTTP proxy such as tinyproxy or Squid, with a username and password.
No proxy is guaranteed to work. A site may block any provider's IPs, or block automated browsers whatever the IP. Test before you buy, from your own computer:
curl -I -x http://username:password@proxy-host:port https://www.example.comA
200or301response means the site answered through that proxy. A403means it's blocked there too.
See also¶
- Allowlisting VisualRunner traffic: the better option when you control the site
- Private Runner: capture internal sites from inside your own network
- Uptime: the "Blocked by site" and "Capture route unavailable" statuses