Before You Start
Prepare the Client and a Working Configuration
This tutorial is for graphical clients built on the Mihomo core. Button locations vary across Windows, macOS, Android, iOS, and Linux, but the workflow is the same: the subscription URL retrieves the configuration, which contains proxy nodes, policy groups, and routing rules; the client loads that configuration and takes over system traffic. Understanding this order keeps different menu names from getting in the way.
If you have not installed a client yet, visit the client download page and choose a maintained version for your operating system. Launch desktop clients normally after installation. On mobile, the first launch may request notification or VPN permissions; approve the VPN permission in step three when you enable the connection. If a client is already installed, continue directly, but close other proxy apps first to prevent them from changing the system proxy or competing for the same port.
You also need a working subscription URL. Providers usually display it in the user dashboard. It is not an ordinary webpage URL and may return YAML configuration or encoded node data when opened. Copy the entire address from beginning to end without including periods, parentheses, or line breaks added by a chat app. If the provider offers multiple client formats, choose one labeled Clash, Mihomo, or Clash Meta.
Step 1
Import the Subscription and Set It as Active
After opening the client, find the “Configuration,” “Profiles,” or “Subscriptions” page. Choose “New Subscription,” “Import from URL,” or the plus button, then paste the complete subscription link into the address field. Use the provider name or purpose as the label, such as “Daily Use,” so multiple configurations are easy to identify later. Before saving, check that the address starts with https://, contains no spaces, and has no extra punctuation at the end.
Click “Import,” “Download,” or “Save.” The client will request and parse the subscription, usually within a few seconds. After a successful import, a new entry appears with its name, update time, or an update button. Do not enable the system proxy yet. Click this entry first to make it the active Profile. A Profile is the client's unit for storing and switching configurations; the subscription URL provides the update source, while the downloaded content is organized into the configuration file the client actually loads.
With the configuration selected, open the Proxies page and check whether policy groups appear. Common names include “Node Select,” “Auto Select,” “Foreign Traffic,” or names defined by the provider. Seeing multiple policy groups and options usually means the subscription was parsed successfully. If the list is still empty, return to the configuration page, click “Update” once, and wait for the update to finish. Avoid clicking Import repeatedly, or you may create duplicate configurations with similar names.
Some clients let you set an automatic update interval. For your first setup, keep the default value. Subscription updates only retrieve the provider's latest configuration; they do not require constant frequent requests. Update manually later if the node list, rules, or policy groups differ from the provider's page. If you manage several configurations, give each a clear name and confirm that the highlighted entry changes after switching.
Status After This Step
- A newly imported subscription appears in the configuration list.
- That configuration is selected as the active configuration.
- Policy groups and available nodes appear on the Proxies page.
Step 2
Choose Rule Mode and an Available Node
After the configuration loads, find “Mode” or the runtime settings. For a first connection, choose “Rule” mode. Rule mode uses the configured rules to decide whether each domain or IP connects directly, uses a proxy, or is handled by a policy group. Local services generally stay direct, while requests that need a proxy use the selected node—this is the most common setup for everyday use.
“Global” mode sends most requests through one proxy policy. It is useful for temporarily checking whether a rule is causing an access problem, but it is not recommended as the default for first-time setup. “Direct” mode bypasses proxy nodes and is useful for pausing the proxy or running comparison tests. Switching modes only changes how traffic is routed; it does not start the core or enable the system proxy. Continue to step three after choosing a mode.
| Mode | Traffic Handling | Best For |
|---|---|---|
| Rule | Routes traffic according to configured domains, IPs, and rule sets | Everyday use; recommended |
| Global | Sends most requests through the same proxy policy | Temporarily testing whether rules cause access differences |
| Direct | Requests bypass proxy nodes | Pausing the proxy or running network comparison tests |
Next, open the “Proxies” or policy groups page. Find the group handling most traffic, then click a specific node. Some configurations offer “Auto Select,” “Failover,” or “Load Balance” policies. For a first setup, choosing a regular node makes connection testing easier to interpret. The displayed latency reflects only one probe, not actual download speed, so there is no need to chase the lowest number. A stable probe and reliable access to the target site matter more than a single reading.
After clicking a node, confirm that a selection marker appears beside it. If the configuration has several policy groups, check where the top-level group ultimately points. For example, if the main group uses “Auto Select,” open “Auto Select” and confirm that it contains usable nodes. If the main group still points to DIRECT, traffic matching that group's rules will continue to connect directly. You do not need to edit every group during first-time setup. Start with the most obvious main selection group, then confirm the result with the access test in step four.
If every node test fails, do not immediately change ports, DNS, or large numbers of rules. Test one or two different nodes first, then check the subscription status on the provider's page. A severely incorrect system clock can also affect encrypted connections, so enable automatic date and time-zone synchronization. For a systematic process covering node timeouts, rule matching, and DNS, see the troubleshooting handbook; this page focuses only on first-connection checks.
Status After This Step
- The runtime mode is set to “Rule.”
- The main policy group points to a working node or an automatic-selection policy.
- At least one node passes a basic connectivity test.
Step 3
Start the Core and Enable the System Proxy
Return to the client's home or settings page and confirm that the Mihomo core is running. Depending on the client, the status may appear as “Start,” “Service Mode,” “Running Status,” or a power icon. Once started, the interface usually shows a running state, and the log page begins recording connections and rule matches. If you see a port conflict, configuration parse error, or core startup failure, fix it first; enabling the system proxy will not forward traffic correctly while the core is not running.
On desktop, turn on the “System Proxy” switch. This points the operating system's HTTP and HTTPS proxy settings to the client's local listening port. Most browsers and apps that follow the system proxy will use it automatically. Starting the core without enabling the system proxy leaves the client running in the background while ordinary browser traffic may still connect directly—a common first-time setup mistake.
Windows users usually only need to enable the system proxy switch. If the client offers “Service Mode” or an administrator component, it mainly adds system-level controls and is not required for every first connection. macOS may display a system confirmation dialog for changing network settings; approve it as prompted. After switching Wi-Fi, Ethernet, or network services, check the system proxy again because each service may store its own proxy configuration.
Android and iOS work differently. Mobile clients usually take over traffic through the system VPN interface, so tapping Connect prompts the operating system for VPN configuration permission. After approval, a VPN indicator appears in the status bar. This local VPN interface passes app traffic to the Mihomo core; it does not mean the device is connected to a traditional corporate VPN. If permission is denied, the client cannot handle other apps' network requests. Tap Connect again and allow the system request.
If a Linux graphical client supports a system proxy, start with its built-in switch. Desktop environments implement system proxies differently, and terminal programs often ignore desktop proxy settings. Use a browser for the initial verification and avoid changing shell environment variables at the same time. If the browser works but terminal commands still connect directly, the core and node are likely fine; configure the terminal environment separately later. See the system proxy not working section for command and desktop-environment differences.
Status After This Step
- The client shows that the Mihomo core is running.
- The desktop system proxy is enabled, or the mobile VPN is connected.
- The startup process shows no ongoing configuration or port errors.
Step 4
Verify the Exit IP and Rule Routing
After connecting, do not rely only on the color of the client switch. The clearest test is to open a new browser window, visit a trusted exit IP lookup page, and note the public IP address and region shown. Then disable the system proxy or mobile connection and refresh the same page for comparison. After enabling it again, the exit details should change with the selected node. A comparison test is more reliable than simply loading a webpage, which may be cached or reachable directly.
After confirming the exit change, test two types of sites: commonly used local sites expected to connect directly, and target sites expected to use the proxy. In rule mode, the two requests may follow different paths; that is normal routing behavior. The client's connection or log page usually shows the domain, matched rule, and final policy. For example, DIRECT means a direct connection, while a policy group or node name indicates proxy use. For an initial check, review only a few newly generated entries rather than reading the entire log.
If the browser accesses sites through the proxy but a particular app still cannot connect, fully quit and reopen that app. Some programs read system proxy settings only at startup, while others use their own proxy configuration. Check for options such as “Use System Proxy,” “Auto Detect,” or manual proxy settings, and prefer following the system. Games, virtual machines, containers, command-line tools, and some store apps may not follow the desktop system proxy directly and require separate configuration.
If the exit address does not change, return to the client and check four things in order: the active configuration is the one you just imported, the mode is Rule, the main policy group has a proxy node selected, and the system proxy or VPN is enabled. Do not change several settings at once. Refresh the exit page after each check so you can identify which step caused the difference.
After verification, keep Rule mode for everyday use. To stop temporarily, desktop users should disable the system proxy before stopping the core; mobile users can simply disconnect the client. If the browser loses all internet access after an abnormal exit, the operating system may still be pointing to the local proxy port. Reopen the client and disable the system proxy, or clear the manual proxy in the system network settings.
How to Confirm a Successful Connection
- The exit IP changes as expected when you enable and disable the connection.
- Target sites are accessible, while commonly used local sites continue to load normally.
- The logs show new requests and their matched rules or policies.
- After disabling the system proxy, ordinary network access returns.
Quick Troubleshooting
Common First-Connection Problems
The checks below cover the most common points of failure during the four-step setup. For systematic troubleshooting of DNS, TUN, port conflicts, subscription formats, and mobile background restrictions, continue to the troubleshooting handbook instead of changing too many advanced options at once.
The subscription imported successfully, but no nodes appear on the Proxies page. What should I do?
First confirm that the new configuration is selected, then click Update once. If it remains empty, the subscription may be returning a format the client cannot recognize, or its status may be invalid. Copy a Clash, Mihomo, or Clash Meta URL from the provider's page, delete the empty configuration, and import it again.
The node passes its test, but the browser's exit IP does not change. What should I do?
A node test only shows that the client can attempt to connect to the target node; it does not prove that browser traffic is entering the client. Check that the system proxy is enabled and restart the browser. On mobile, confirm that a VPN indicator appears in the system status bar.
All websites stop loading after I enable the system proxy. What should I do?
Disable the system proxy first to restore normal network access, then confirm that the core started successfully. If the client reports a port conflict or configuration error, fix that error first. When the system proxy points to a local port with nothing listening, all browser requests fail.
Only some websites are inaccessible in Rule mode. What should I do?
Temporarily switch to Global mode and test again. If Global mode works, the issue is probably related to rule matching or policy-group selection. If Global mode also fails, check node connectivity, subscription status, and the device's network first. Switch back to Rule mode after testing, then continue with the troubleshooting handbook based on the logs.