Tutorial / 05 Proxy mode and rules

Setup

Proxy mode and rules

Decide first which traffic goes through a node, and which stays local

After a successful connection, you still decide how traffic moves. Shadowrocket matches domains, suffixes, keywords, IP ranges, or GeoIP, then proxies, goes Direct, or rejects. Menu names in different versions may say Proxy, Config, or Scene. The meaning is close.

Three common modes

Mode Behavior When to use it
Config / Rule The rule set decides: matches go through the proxy; the rest go Direct or are rejected by a rule. Daily default. Sends less unnecessary traffic off the local network.
Proxy / Global Sends as much traffic as it can take over through the current node. Comparison. If a site fails in rule mode, switch here to see whether rules misclassified it.
Direct Almost no traffic goes through a node. Debugging. Confirms the local network still works after you turn the proxy off.

Stay on rule mode day to day. Global is for a short comparison, not a long-term default. Direct is almost the same as not using a proxy.

Where rules come from

A subscription sometimes ships rules. You can also import a rule file from a URL or iCloud Drive. The principle: start with one list whose source you understand. Stacking several unknown lists makes them overwrite each other. It looks like “a site that just worked suddenly goes Direct or times out.”

Before you edit rules yourself, confirm three things: whether the match is a domain, an IP, or a process; whether the action is proxy, Direct, or reject; and where the rule sits, so a line above it does not steal the match. After a change, test at once with a familiar site. Do not change many lines and then test.

Per-app

If you want only some apps on a node, or the reverse on Direct, use per-app / Scene inside the app. Do not change another VPN in system Settings.

There are two layers: the system must already allow Shadowrocket’s VPN configuration before per-app settings in the app take effect. If the system does not allow it, nothing you set in the app matters. After you change the per-app list, fully quit the target app and open it again.

DNS and On-Demand

If some sites will not open or resolve oddly, DNS may be involved. Shadowrocket supports remote DNS, DoH / DoT / DoQ, and local mapping. If you have no clear need, keep the default or whatever the subscription ships. Filling in a public DNS without understanding the split can send a domain that should stay Direct to the wrong place.

On-Demand can wait to handshake until a specific network or app triggers it, which helps battery life. Turn it off while you debug, so you do not think the UI is connected when the handshake has not happened yet.

How to confirm it is a rule problem

One comparison is enough: same node, rule mode fails and global works, so rules marked that domain Direct or reject. If global fails too, change the node first, then check DNS. Do not edit rules, change nodes, and change DNS together. Change one thing, or you cannot tell which step worked.

The request log can show whether a domain actually went through the proxy or Direct. That is closer to the fact than reading Connected alone. A full description of capabilities is in About.

Leave advanced items off for now

HTTPS decryption, script filters, and multi-hop forwarding are debugging or advanced features. Daily connections do not need them. If you do not understand certificates and the risk, leave them off, and do not stack unknown scripts for “speed.” After you change the split, back up first, so a later reinstall does not leave you with only a subscription URL and no memory of local rule edits.