HotS Proxy: Account Security, the Compliance Line and Traffic Scope
Heroes of the Storm — HotS for short — is launched through a desktop application, and the game runs as its own process. This page explains the network behaviour of the two processes, how account region and two-step verification affect the setup, and which traffic can actually enter the tunnel.
Traffic sharesThe weight of login, patching, match streaming and telemetry items.
02
Account and regionTwo-step verification, new locations and region binding.
03
Compliance limitsWhere things stand with integrity checks and terms of service.
04
TCP or UDP?See on your own machine which item can enter the tunnel.
When discussing the network side for HotS, you have to separate the two processes. The launcher application handles account login, patch checks and file downloads; the game opens as a separate process and uses its own channel throughout the match. A proxy definition is not automatically applied to both in the same way, because the two applications may read network settings differently.
The second distinction is at the transport layer. Menus, profile pages and download requests are ordered-delivery jobs that run over TCP. State updates during a match strike a different balance. Which item uses which protocol should be based on measurements on your own machine, not on forum claims; how to do that is explained below.
Finally, let us state what is out of scope: this page does not explain region changing, account transfers, multi-accounting or defeating the integrity checks that run alongside the client. Complying with the publisher's terms of service is the user's responsibility, and a network setting does not change that responsibility.
How is network work divided in a HotS session?
The session opens with the launcher's account verification. This item is small but decisive: the session identity is established here, and the address visible on the server side is recorded at this step. Next comes the patch check; if an update is available, the file download kicks in and single-handedly defines your entire network profile for that day. On an evening with no patch, the same item is close to zero.
When the game opens, the client interface generates its own requests: profile, hero list, collection and shop screens. These are again web-like requests and tend to fall within the scope of a proxy definition. Once the match starts, the state stream takes over: small packets, high frequency and a latency-sensitive channel.
The fifth item sits where most users never think to look: voice chat and telemetry. Voice communication usually runs over a separate channel and may not share the fate of the match channel. Telemetry, meanwhile, sends small packets in the background. Considering these two items separately when assessing the scope of your setup heads off problems of the "everything works but voice doesn't go through" variety.
Note
The network profile of a patch day and an ordinary evening are not alike. If you choose your egress based only on match evenings, you will run into surprises on quota and bandwidth on update days.
DIAGRAMItem weights across a session
You can scroll the diagram horizontally to inspect it
Column heights are not measurements but representative shares showing the weight of the items relative to one another; on a day with no patch, the second column drops to almost zero.
Account region, two-step verification and location changes
The region an account is tied to is an account property independent of the network path. The server group you play on, your friends list and purchased content are bound to that region; changing the country of your egress address does not carry that context over. Accepting this up front prevents you from forming the wrong expectations of the setup.
The second topic is verification behaviour. Publisher accounts may request an extra step for logins from an unusual location or a new device; sending an email notification is common practice. If two-step verification is enabled, this step is a security gain for you, not an obstacle. Rather than turning it off, the right approach is to reduce how often verification is requested by keeping the egress address fixed.
Use a single egress per account and do not change it unless necessary.
Choose an exit country consistent with the account's usual country of use.
Keep two-step verification enabled; keep your recovery details up to date.
Do not share credentials; account sharing is against the terms of service.
If you need to change the egress, do it while the session is closed, not mid-match.
On the privacy side, the point to watch is what the egress server sees. Even if the connection content is encrypted, which addresses you go to can be visible and logged on that server. Provider choice is therefore a trust decision, not a technical one; what logging policies actually mean proxy logs and privacy article.
Integrity checks and terms of service: where should you stop?
Protection components that run alongside the client look at the integrity of the running process, not at your network path. A proxy changes none of the things those checks look at: the state of game files, whether memory has been tampered with, and whether the client is running as expected are all independent of your network setting. A proxy is therefore neither a tool nor a risk mitigator in that area.
This needs to be said plainly, because the two are frequently confused in online discussions. The only thing a proxy changes is where the server considers your connection to have come from. The list of things it does not change is long: hardware and client fingerprints, account history, in-game behaviour records and telemetry. Decisions taken on an account are not reversed by changing the network path.
Caution
This page does not describe any method for disabling protection components, circumventing regional restrictions, or dealing with sanctioned accounts. Egress use is covered only in access, network management, testing and privacy scenarios; compliance with the terms of service rests with the user.
The legitimate use cases are narrow but real. Leaving a corporate network from a fixed address, testing how a client behaves from a different country, keeping the egress address predictable in environments such as internet cafés or shared gaming lounges, and not wanting target addresses to be visible to your ISP are among them. In these scenarios the goal is not an in-game advantage but managing network behaviour.
Which traffic can enter the tunnel and which cannot?
The distinction begins at the transport layer. An HTTP proxy opens a tunnel for HTTPS using the CONNECT method, and that tunnel carries only TCP bytes. UDP never enters this tunnel. SOCKS5, on the other hand, can carry UDP by a separate method: the client establishes a control channel, requests an association, and sends its datagrams wrapped in a small header to the relay address the proxy provides.
This header is the protocol's most concrete detail. It contains reserved fields, fragmentation information, the address type and the address–port pair of the actual destination; the game data is carried at the very end. In other words, UDP forwarding is not an "on or off" switch but an extra wrapping job on every datagram. If the provider does not support it, the request is refused and the setup silently carries only the TCP items. When choosing which protocol suits which job, the proxy protocol selection guide offers a useful framework.
How do you verify this on your own machine?
Measure instead of guessing. On Windows, the network tab of Resource Monitor lists running processes and the connections they have opened; on the command line, you can reach the same information by filtering the netstat -ano output by the game's process ID. Looking at this list after opening the game and entering a match shows directly which item is TCP and which is UDP. Whether an application offers a SOCKS5 field is a separate question; applications that support SOCKS5 explains this distinction with examples.
DIAGRAMThe fields of a datagram carried over SOCKS5
You can scroll the diagram horizontally to inspect it
Field widths are representative rather than to scale; the key point is that every datagram is sent with a wrapper carrying its destination information.
Egress plans for the HotS client
If stability and a fixed address are your priority, a static solution stands out; if update-day volume is the deciding factor, a high-bandwidth egress does.
Choose whichever you need from our residential proxies, datacenter proxies, IPv6 and ISP solutions. Every plan comes with unlimited options, 99.9% uptime, rotating proxies, sticky sessions and 24/7 support. Ideal for web scraping, ad verification, SEO monitoring and digital data collection.
ISP ProxyStatic Turkish IPs registered to an ISP
ISP-registered static Türkiye IPs; they combine datacenter speed with the reputation of a real carrier. Ideal for long sessions and low-ping use.
On social platforms, which network class the egress belongs to matters; with a game client the picture is different. The game server does not try to place you in a marketing profile; it only wants the connection to be stable. What is decisive here is therefore not the class but three concrete qualities: latency stability, bandwidth and address persistence.
Static egress hosted on a provider network generally gives the most balanced result across these three: the address is fixed and the line has datacenter-grade stability. Pure datacenter egress is strong on bandwidth and offers an advantage on patch days. With solutions that go through a residential subscriber line, the speed of the line is not under your control; with mobile egress, carrier-level sharing and variable latency make for the most difficult combination for a real-time channel.
Do not settle for a single measurement when deciding. Measure the same egress at different times of day and look at the distribution of the results; what matters is the variation, not the average. To measure from your own line you can use ping test and read about the components that make up latency in what proxy latency is . An intermediate hop generally increases latency; decide whether to accept that cost by looking at your scenario.
DIAGRAMSuitability of egress types for this scenario
You can scroll the diagram horizontally to inspect it
The scores are not real measurements but relative suitability values assigned according to the stability–bandwidth–address persistence trio.
Where should the setting go, and how should the scope be limited?
Because the launcher and the game are separate processes, the scope decision is also made on two fronts. A definition at the operating-system level is a candidate to affect both, but there is no guarantee that any given application will read it. Application-based routing is more precise: you choose which process leaves through the tunnel, and the rest of your work stays on your usual line.
Point of definition
Traffic covered
What to watch for
Operating system setting
All applications that read this setting
Update services also leave through the tunnel
Browser profile
That profile only
Does not cover the game client
Application-based rule
Selected processes
Add the launcher and the game separately
Router level
Every device on the network
Real-time UDP streaming is out of scope in most setups
The format of connection details does not vary by provider: a hostname, a port, and a username and password if required. As an example, you can think of the fields proxy.example.com, 8080, username and password ; the real values are in your panel. The port number itself does not determine the protocol, so do not enter values without reading which line in the panel belongs to which protocol. For the steps on the system side, Windows proxy settings article.
Do not skip verification after setup. Confirm with an independent check that the egress is live and that you are leaving from the address you expect; proxy checker tool is a quick starting point for that. Do not run two different routing layers at the same time: diagnosis is impossible in a setup where you cannot tell which one is in effect.
Symptom, likely cause and order of checks
Symptom
Possible cause
Check
The launcher logs in but the game will not connect
The two processes are leaving by different paths
Check that the game is also defined in the application-based rule
Patch download very slow
The egress bandwidth or quota limit
Read the remaining quota and try the download directly over the line
Voice chat is not working
Voice runs over a separate channel
Assess the UDP situation and the scope together
Additional verification is requested frequently
The egress is changing or the country is inconsistent
Switch to a fixed exit, match the country to the account
Sudden disconnect during a match
The control channel closed or the session timed out
Extend the session window and measure stability
Certificate warning
The TLS session is being re-established through an intermediary
Do not click through the warning on an exit you do not know
The order of diagnosis is this: is the egress live, is the address in the right country, and which process is using this egress. Skipping the third question is the costliest mistake, because a process left out of scope keeps leaving over your usual line without generating a single error, and the setup appears to be working.
When does using an egress make sense, and when is it unnecessary?
The unnecessary case is the most common one: if you are playing from your own home with an account in your own region, adding an intermediate hop brings you nothing but extra latency, cost and diagnostic burden. In that case the right decision is not to set it up at all.
The cases where it makes sense depend on specific scenarios. If you need to leave a corporate or shared network from a fixed address, if you are testing client behaviour from another country, if you want the egress to stay predictable in shared lounges and café environments, or if you do not want target addresses to be visible to your ISP, then an egress becomes meaningful. Even in these scenarios, set your expectations correctly: what you gain is visibility management, not game performance.
One final reminder: the scope is exactly as large as what you have defined. A proxy is not a layer that wraps the entire device but a routing rule written for specific processes. Setups that accept this difference run smoothly; those built on the assumption that "everything now goes through the tunnel" give themselves away in the first match.
Frequently asked questions about Heroes of the Storm and proxies
01Can all HotS traffic pass through a proxy?
In most setups, no. Items that run over TCP — such as login, patching and interface requests — tend to fall within scope. Real-time streaming requires a setup that can carry UDP, and both the provider and the client-side layer must support it.
02Are the launcher and the game configured separately?
In practice, yes. They are separate processes and may read network settings differently. If you use an application-based rule, you need to add both to the list; adding only the launcher causes the game to leave over your usual line.
03Does connecting from a different country put my account at risk?
Connecting to your own account with your own credentials is not a rule violation; however, an unusual location can trigger additional verification and notifications. Choosing an address once and not changing it during the session is the single setting that noticeably reduces how often verification is requested. The account region, meanwhile, is independent of the network path.
04Does a proxy affect integrity checks?
No. These checks look at the state of the running process, not the network path; a proxy changes nothing in that area. A proxy only changes where the server considers your connection to have come from. Methods aimed at disabling protection components are not the subject of this page.
05How do I see whether my client uses TCP or UDP?
Measure it on your own machine. On Windows, the network tab of Resource Monitor lists open connections per process; on the command line, netstat -ano filtering the output by the game's process ID gives the same information. Checking after you have entered a match produces the most accurate result.
06Why do downloads slow down on update days?
File downloads dwarf every other item in a session by volume and depend directly on the egress bandwidth. A concurrent connection cap can also limit the parallel streams opened by the download manager. On plans billed by data, a single large update consumes the quota quickly.
07Which egress type is more suitable for this game?
What matters is not the network class but three qualities: latency stability, bandwidth and address persistence. Static egress hosted on a provider network generally delivers the most balanced result across all three; mobile egress is the most challenging option for a real-time channel because of its variable latency.