📁 Apple iOS VPN Tutorial

Shadowrocket Configuration Notes: Routing, Policy Groups, and Performance Tuning

66 views 7 min read
Shadowrocket Configuration Notes: Routing, Policy Groups, and Performance Tuning

Shadowrocket Configuration Notes: Routing, Policy Groups, and Performance Tuning

You've installed Shadowrocket, imported a subscription, and connected to a node. That's where most people stop. It works, so why bother, right? But after using it for a while, you start noticing things: domestic sites feel slower than a direct connection, one app keeps spinning, subscription updates occasionally fail, and your battery drains faster than usual.

None of these are Shadowrocket's fault. They're signs that the configuration is only half done. This note skips the installation steps and focuses on the configuration decisions that actually affect your daily experience.

The rule priority trap

Shadowrocket matches rules from top to bottom, stopping at the first hit. That's simple enough, but many people trip over one thing when writing custom rules: placing a broad rule before a specific one.

Take this example:

DOMAIN-SUFFIX, google.com, Proxy
DOMAIN, api.google.com, Direct

The second line is meant to say "api.google.com should go direct." But because the domain-suffix rule on the first line already matches api.google.com, the second line never executes. The correct order is to put the exact DOMAIN rule before the DOMAIN-SUFFIX rule.

Another common oversight is incomplete domain coverage for services like ChatGPT. Many people only configure chatgpt.com, but OpenAI also relies on cdn.oaistatic.com, oaiusercontent.com, and others. Missing any of these can result in a page that loads but a chat that never sends. If you use multiple AI services, check the Wraith VPN blog for our AI service domain list and fill in the gaps.

If you'd rather not maintain rules manually, importing a community-maintained configuration is easier. The import method is the same as a subscription: Shadowrocket → Config → Import from URL. After importing, tap the configuration to set it as active.

Policy group tolerance: why your node keeps switching

Shadowrocket's policy groups support the url-test type, which automatically selects the node with the lowest latency. Many people enable this and then notice nodes switching back and forth, occasionally interrupting connections.

The problem is the tolerance parameter. The default is 100ms, meaning a new node won't trigger a switch unless it's at least 100ms faster than the current one. With many nodes and similar latencies, this can cause frequent switching and a worse experience.

The fix is simple: increase the tolerance to 200ms or 300ms. That way, switching only happens when a new node is clearly faster, avoiding unnecessary interruptions.

Policy group type also matters. Select is good for fixed exit IPs, such as services that require login verification. Fallback is for primary-backup setups, switching only when the primary fails. Url-test is for everyday browsing, automatically picking the best route. If you subscribe to multiple providers, consider grouping by region and referencing the group name in your rules. This approach is similar to the proxy group logic covered in our Clash for Android guide.

Configuration mode vs global mode: what's the difference

The "Global Routing" option at the bottom of Shadowrocket's home screen has four choices. Many people leave it on "Proxy" mode, thinking it's the simplest. But "Proxy" means all traffic goes through the proxy, including domestic sites, which naturally slows things down.

The correct daily choice is "Configuration" mode. It uses the rules in your configuration file to decide which traffic goes through the proxy and which goes direct. Domestic sites connect directly, overseas services go through the proxy—this gives you the best balance of speed and stability.

"Direct" mode is mainly for troubleshooting, like checking whether a site fails because of the proxy. "Scenario" mode is for users with multiple usage contexts—home, office, outdoor—each with its own rule set, but the configuration cost is high and most users don't need it.

If domestic sites still feel slow after switching to Configuration mode, check whether the GEOIP rule correctly points Chinese IPs to direct. If the rule is fine, the issue might be DNS resolution going through the proxy channel—covered in the next section.

DNS settings: the silent experience killer

DNS leaks are a subtle problem in Shadowrocket configuration. The symptom: the proxy connection works, but some sites won't load, or they load the domestic version of the content.

The cause is usually DNS requests not going through the proxy channel, instead being resolved by the local DNS server. The other side can infer your real location from the DNS request source and either deny service or return the wrong content version.

Checking is easy: visit a DNS leak test site and see whether the DNS server location matches your proxy node location. If not, enable "Remote DNS" or configure DNS over HTTPS in the settings.

Another related setting is "Local DNS Mapping." If misconfigured, it can cause domains to resolve to wrong IPs. When you see "some sites work, some don't," check here first. If you're using Wraith VPN's subscription, DNS leak protection is enabled by default. If you don't have an account yet, visit the pricing page to get started.

Performance and battery: a few adjustments worth making

Shadowrocket in Configuration mode only processes traffic that needs the proxy, so it's already fairly power-efficient. But if you feel battery drain is still high, check these settings:

Disable UDP forwarding. If you don't game or make voice calls, you can turn this off. It reduces unnecessary resource consumption without affecting browsing or video playback.

Enable On-Demand. Settings → On-Demand → enable "Reconnect." The connection recovers automatically after network fluctuations, so you don't have to toggle it manually.

Avoid long sessions in Proxy mode. Global proxy mode routes all traffic through the proxy, increasing CPU and network usage. Stick with Configuration mode for daily use.

If you're also using other proxy clients like Streisand or FlClash, keep only one client's VPN session active at a time to avoid routing table conflicts and unexpected battery drain.

Troubleshooting subscription refresh failures and node issues

Subscription refresh failures aren't always the provider's fault. Check these in order:

First, switch networks. Turn off Wi-Fi and use cellular data, or vice versa. Many subscription links are blocked on certain networks; switching usually fixes it.

Second, check whether the subscription link has expired. Some providers rotate subscription URLs periodically—re-copy it from your user center. Wraith VPN's subscription links can be re-copied from the user center at any time, and the format notes are on the download page.

Third, confirm the subscription format matches. Shadowrocket uses a dedicated format that's not interchangeable with Clash or V2Ray. When copying, make sure you select the right client format.

Fourth, clear Shadowrocket's cache. Settings → Clear Cache, then re-import the subscription.

If none of these work, check the FAQ page for similar cases, or contact us for help.

Final thoughts

Shadowrocket configuration isn't a one-time task. Subscriptions update, rules iterate, and usage scenarios change. Two habits are worth building: first, update your subscription and rules periodically; second, when something goes wrong, check "Routing Mode" and "Rule Order" first—most connection issues trace back to these two entry points.

If you don't have a Wraith VPN account yet, visit the pricing page and start with the Basic Starter or Standard Plus plan. Shadowrocket subscription details are available in your user center.

Recommended High-Speed VPN

All-in-One Package

Traffic: 500G · Devices: 10 · 365 days

Basic Unlimited Traffic

Traffic: 99,999G · Devices: 10 · 365 days

Standard Plus Package

Traffic: 200G · Devices: 10 · 365 days

HD Streaming Package

Traffic: 300G · Devices: 10 · 365 days

About This Article

This article is part of our Apple iOS VPN Tutorial series — covering VPN setup, configuration, privacy, and network optimization for Wraith VPN users.

Wraith VPN provides global high-speed nodes, multi-device support, stable access to streaming media, anonymous USDT payment, and a strict no-logs policy.

Looking for a plan? Visit our VPN Packages page. For common questions, see FAQ.

Last updated: October 3, 2026