Shadowrocket HTTPS decryption installs a user root CA and splits TLS on the device. You get real hostnames in the rule log. You also break certificate pinning and widen the window for any other MITM that can use that CA. Ten minutes on your own phone is a debug tool. Banks, work mail, and a child’s iPad are not “use cases.” Toggle off is not enough—remove the certificate.

How to generate the CA lives in HTTPS decrypt. This page will not walk the taps. If you cannot see a host, try exception order first. Channel: download. Apple’s cert note: manage certificates.

Three trust layers you just took apart

The browser: Safari will accept site certs minted by your CA. The trust store does not know “this CA is only for Shadowrocket.” Full Trust on a user cert is a device-wide decision.

App pinning: banks, some clouds, MDM apps pin a SPKI. The chain is valid for the OS and invalid for the app: white screen, login loop, crash without a useful code. That is you, not the pop. Disable decrypt; do not rotate subscriptions.

The path: decrypt forces the HTTP engine. Modules, REJECT, and rewrite scripts then operate on plaintext. Module misfires: REJECT modules. Decrypt + ad module + remote JS is an un-debugable sandwich.

TargetWhat decrypt doesCall
Your rule, ten minutesReal SNI in the logOK, then off
Banking / paymentsPinning or scary warningsStay off, Direct the hosts
Work mail / supervised deviceFights corporate PKINever
A kid’s iPad “for filtering”A root that stays for monthsUse Screen Time, not MITM

The toggle is off; the CA is still in VPN & Device Management

Settings → General → VPN & Device Management still listing a Shadowrocket CA means you did not finish. After deleting it, Safari should not be using that issuer. If you ever tapped Full Trust, unwind that too. Two leftover CAs: delete the older date so iOS does not pick a stale chain.

Config backups copy the MITM flag. A new iPhone will nag you to install a certificate. Restore the subscription; do not restore “decrypt is a lifestyle.” See backups. A sideloaded IPA plus decrypt is trusting an unknown signer. This site only documents the store channel on the download page.

Other people’s phones are not a lab

Reading your own traffic on your own handset is not the same as installing a CA on someone else’s. The latter is their mail and their bank. Shadowrocket does not ship MITM as a family SKU. When a colleague asks you to “look at the rules,” do not tap Full Trust on their device.

Decrypt on cafe Wi-Fi does not make you safer; it parks another copy of plaintext on the phone. Certificate prompts during a Wi-Fi → LTE handoff will cancel the VPN extension—handoff. For privacy, run a normal tunnel with decrypt off.

Hard stop

Any payment app, government app, or company portal showing a cert error: disable decrypt, do not tap Continue. If the HOST rule already names the site, you do not need MITM. Policy-group failures are not a decrypt problem—groups.

Ten minutes and you still cannot see a hostname: stop. Write URL, hit rule, decrypt on/off. Then guides and FAQ. An expired plan will not resurrect under MITM—expiry. Install from the download page store path only.