Clash Quick Start: From Subscription to Connection Check
Load your configuration first, then decide how to route traffic. Follow the four steps below, then check the result under Connections or Logs. Save detailed proxy group, DNS, and TUN settings for when you need them.
Get your subscription link and client ready
After installation, make sure the client opens before importing a configuration.
This guide assumes you already have a working Clash-compatible subscription link. Your provider supplies the link, which usually points to a downloadable configuration rather than a single proxy node. Copy the full URL—not the address of the subscription page. If your provider offers multiple formats, choose one labeled Clash or Mihomo. Subscription links may contain private connection details, so don’t post them publicly or process them with unfamiliar online tools.
Open the installed client and locate three areas: Configuration imports and activates subscriptions; Proxy shows proxy groups and lets you choose an outbound node; Overview or the home page controls the system proxy and shows the client status. Menus vary, but the workflow is the same. On mobile, be ready to approve the VPN prompt from your operating system. You only need to grant permission when starting a connection. If an old profile is already listed, note which one is active so you don’t mistake it for the new subscription after importing.
For your first setup, keep the test path simple: load one subscription, select an available outbound node in Rule mode, enable the device’s proxy connection, then check an actual request. Avoid changing DNS, TUN, ports, and multiple override files all at once. If something goes wrong, changing too many settings makes it harder to identify the cause.
Import a Subscription and Set It as Active
Saving the link is only the first step: make sure it downloads successfully and activate the profile.
In the client, open Configuration or Subscription and find the option to add a remote profile. Some clients use a plus button; others offer Import from URL or Import Subscription. Choose the link-import option and paste the full subscription URL into the URL field. If there’s a name field, enter a label that’s easy to recognize, such as your provider’s name. Confirm and wait for the client to download the configuration; the new entry should then appear in the profile list. Don’t paste the subscription page title into the URL field or enter the URL as a node name.
When the new entry appears, check for a successful download message or see if you can open the configuration. Then select Use, Enable, or the selection indicator to make it active. This matters: some clients save the new subscription but keep running the previous local profile. Return to Overview and check that the active profile name has changed. Then open Proxy and look for the subscription’s proxy groups and nodes. Seeing the groups means the configuration has at least been parsed and loaded, so you can now choose an outbound node.
If no new entry appears after saving, check that the link is complete and has no extra spaces, then make sure your device can reach the subscription URL. If the entry is there but shows a parse error, ask your provider whether the link serves a Clash-compatible configuration. A single-node share link or a node list in another format may not work as a complete profile. If an update fails but the old proxy groups are still visible, they may be cached from the previous download—not proof that the latest update succeeded. Fix the import issue before changing proxy modes.
You’re done with this step when the new entry appears in the profile list, is active, and has expandable proxy groups on the Proxy page. To refresh the subscription later, return to the same page and use Update or Refresh. Afterward, check that the active profile and its proxy groups have loaded correctly. If the client offers an automatic update interval, set it to suit your needs; there’s no need to change the default for your first connection.
Choose a Proxy Mode: Start with Rule
The mode determines how requests are assigned to proxy groups; each group determines the outbound route.
Once the profile has loaded, open the proxy mode selector under Overview or Settings and choose Rule. Some clients label this mode Rule. In Rule mode, the client matches requests against the rules in the active configuration and routes them to the specified proxy group, directly, or blocks them. It’s a good place to start because you can check that traffic requiring a proxy and traffic that should connect directly are handled separately, rather than sending every request through the same route.
Next, open the Proxy page. Your configuration may include groups named Node Select or Auto Select, or groups named by your provider. Open any group that requires manual selection and choose an available node, or select an automatic group if one is provided. If a group points to another group, follow the selection chain to check the final outbound route; the top-level group name alone doesn’t tell you which node is in use. Group names vary by subscription, so use the list in your client. When you’re done, return to Overview and confirm that the mode is still Rule and the active profile is the one you just imported.
Global mode sends requests covered by the client’s routing scope through the selected outbound route. Use it briefly to check whether a problem is caused by rule matching. Direct mode bypasses the proxy route and can help you compare against your device’s normal network connection. Both modes can aid troubleshooting, but don’t leave Global mode on just because a website won’t load. Note the issue in Rule mode, switch modes briefly for comparison, then switch back to Rule to make the difference easier to pinpoint.
Proxy mode is not the device-wide on/off switch. Even with the right proxy group selected, your browser may not be sending requests to the client yet. Until you enable the desktop system proxy or grant VPN access on mobile, the choices on the Proxy page usually only configure the outbound route. After choosing a mode and proxy group, continue to the next step to connect your device to the client. For rule syntax, proxy group types, and rule set maintenance, see the Advanced Config guide. You don’t need to change any of these settings for your first launch.
Connect: Enable the Device’s Proxy
On desktop, start with the system proxy. On mobile, approve the VPN prompt.
On Windows or macOS, return to Overview and turn on System Proxy. The client points your system proxy to a port it monitors locally. Browsers and apps that follow system proxy settings can then send requests to the client. Once the toggle is on, keep the client running; don’t quit it from the system tray or menu bar. If there’s also a Start Core or Run button, make sure the core is running. With the system proxy on but the core stopped, requests go to a local port with no service listening.
On Android or iOS, find the connection button on the home screen and tap it. Your operating system will usually ask for permission to create a VPN connection. Read the prompt and approve it, then check for a VPN indicator in the status bar and a connected status in the client. This VPN is the mobile operating system’s way of connecting the client to the network; it doesn’t mean the subscription loaded correctly. If no permission prompt appears, check for configuration or permission errors in the client. If another app is already using the VPN interface, resolve the conflict before trying again.
On desktop, not every app follows system proxy settings. Browsers are usually a good first test, but some apps use their own proxy settings or network stack, or ignore the system proxy entirely. First get the basic workflow working with an app that follows system proxy settings; then decide whether you need TUN mode. TUN changes which device traffic the client can capture and may also involve system permissions, routing, and DNS. Enabling TUN and the system proxy at the same time during your first connection makes it harder to tell how requests are being routed. To capture traffic from more apps, follow the TUN section of the Advanced Config guide for your device.
If your connection stops working as soon as you enable the system proxy, return to Overview and check that the core is running and the right profile is active. Then make sure the listening port shown in the client matches the port configured for the system proxy. The mixed-port setting commonly accepts both HTTP and SOCKS connections, but use the port configured in your client rather than assuming an example value applies to every device. Leave the connection settings as they are for now and move on to the verification step to check real requests.
Verify the Connection: Check Requests, Not Just Toggles
Check one proxied request and one expected direct request to confirm that routing matches your configuration.
Keep the client connected and open a website you normally access through a proxy and expect to work. Once it loads, switch to the client’s Connections or Logs page and look for the domain you just opened. Connection details usually show the destination, matched rule, proxy group, and final outbound route. Fields vary by client, but confirm at least that the request reached the client and wasn’t sent through an unexpected direct route. The home page’s Connected status alone doesn’t show whether your browser is using the active configuration.
Next, open a website that should connect directly under your current configuration and check whether its new connection is routed directly. The goal isn’t to compare website speeds; it’s to confirm that Rule mode separates the two types of traffic. If both sites load but the logs show the same outbound route for each, check that Rule mode is still active and that the subscription’s rules match your expectations. If the client shows the matched rule, note its name before deciding whether to change the configuration. Don’t rewrite the entire config.yaml just because the result differs from what you expected.
If a website won’t load and there are no new connection entries in the client, the problem is likely happening before traffic reaches it. On desktop, check the system proxy toggle and whether the browser has its own proxy settings or uses a connection method that ignores system settings. On mobile, check VPN permission and the client’s connection status. If there is a connection entry but it went to the wrong proxy group, revisit the group selection on the Proxy page and check that the active profile hasn’t reverted to an older one. If the entry shows the expected outbound route but the site still won’t load, check whether the node is available, the subscription is up to date, or the website itself is having issues. Check in this order—whether a record exists, which rule matched, and which route was used—to find the cause more easily than by toggling everything repeatedly.
After verification, keep track of the active profile, mode, and proxy group selection. If you later run into subscription update failures, DNS resolution problems, port conflicts, or apps that won’t route through the client, consult the Advanced Config guide. To repeat the setup, start again with Import a Subscription and check each step; there’s no need to delete all your existing profiles. When you’re done, turn off the system proxy or disconnect on mobile, then confirm your device’s network settings are back to the expected state.