In Shadowrocket, nodes pick the exit; rules pick the passengers. Flip to global/Proxy first. If that browses, the node is alive and the matcher is wrong. Banks and campus apps want Direct; browsers that need an egress want Proxy.
Many people never open the profile after import. Defaults rarely match your bank-plus-browser mix.
Global before bypass
If global also fails, you have a node or network problem—see grey nodes—not a missing exception.
DIRECT / PROXY / REJECT
| Action | Typical | When wrong |
|---|---|---|
| DIRECT | Bank, LAN, campus | Video CDNs sneak home; homepage without playback |
| PROXY | Safari, geo apps | System WebView omitted |
| REJECT | Optional ad hosts | Login callbacks die |
Policy groups wrap URL Test or fallback. Remote rule refresh can silently keep yesterday’s bypass list. Change one domain class at a time and verify with one screen in one app.
Streaming conflicts: streaming. Decryption is not a splitter: MITM. Download, FAQ, guides.
Field questions tied to this guide
- Config vs node? The node is the tunnel. The profile is the matcher. Handshake ≠ that app uses the tunnel.
- Temporary global? Switch the group or top mode to Proxy for three minutes. If the page loads, the node is fine.
- Where should rule files come from? Your provider’s docs or a remote set you understand. Skip giant mystery lists with redirects.
- Rules made it slower. Huge sets and failed remote updates queue lookups. Shrink the set before blaming the exit.
Change one control, then retest
While working through “Shadowrocket rules and policy groups: Proxy, Direct, and a global sanity check”, write the download-page version, mode, protocol, and node name on the first line of a note. After each toggle, run one check only: 1.1.1.1/help or the exact page that failed. Changing Kill Switch, split rules, and nodes together makes the next failure un-debuggable. Get Shadowrocket packages only from the download page; permissions and device limits live in the FAQ and guides.
On office or hotel networks, finish captive portals and clear leftover PAC entries before you decide this article’s failure mode applies. A cellular A/B exposes router DNS and parental filters quickly. Avoid hammering login on a second device during the test so session kickouts are not mistaken for radio drops.
Pin the combination that works—SSID, node, protocol—and reuse it on that network instead of starting from Auto every time. Keeping slug rocket-rule-policy-group as your note title makes the write-up searchable later.
When to stop and change layers
After five identical failures, stop. Recheck the documented build, confirm a single tunnel client, ensure Kill Switch was not blocking a portal, and verify the browser is not Direct in a split list. Stopping is how you escape the wrong layer.
When you ask for help, include time, SSID, mode, protocol, node names, and steps already tried. After recovery, verify egress in a clean browser so cache does not fake success, then write the split list or favorites back into your notes before the next reinstall.
Extra pass for “Shadowrocket rules and policy groups: Proxy, Direct, and a global sanity check”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Shadowrocket.
Extra pass for “Shadowrocket rules and policy groups: Proxy, Direct, and a global sanity check”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Shadowrocket.
Extra pass for “Shadowrocket rules and policy groups: Proxy, Direct, and a global sanity check”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Shadowrocket.
Extra pass for “Shadowrocket rules and policy groups: Proxy, Direct, and a global sanity check”: retest three minutes on a second network and confirm the download page build. If only one app fails, inspect split membership; if everything fails, inspect permissions and DNS first. One change at a time remains the fastest habit when debugging Shadowrocket.