Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

How to Configure a Proxy in Shadowrocket on iPhone

Add an authorized proxy server to Shadowrocket, connect it on iPhone, test routing and latency, and avoid common privacy and DNS configuration mistakes.

Table of Contents

Shadowrocket is an iPhone and iPad network client that can route traffic through proxy servers you configure. The app does not automatically give you a free proxy service: you need valid server details from a provider, employer, school, or server you administer.

A proxy changes how selected traffic reaches the internet, but it does not guarantee anonymity, encryption, or safety. The result depends on the protocol, rules, DNS settings, server operator, and apps being used.

What you need

  • An iPhone or iPad with Shadowrocket installed from the legitimate App Store listing available in your region.
  • A proxy you are authorized to use.
  • The correct protocol, hostname or IP address, port, and—when required—username and password.
  • Any encryption method, key, certificate, or plugin settings required by that proxy type.

Do not use credentials copied from public “free proxy” lists for sensitive browsing. Such servers may be unreliable, log traffic, inject content, or disappear without notice.

Protocols and what they mean

TypeTypical useImportant limitation
HTTP or HTTPS proxyCompatible web trafficCoverage and encryption depend on the application and connection type
SOCKS5General proxying for supported TCP/UDP trafficSOCKS5 itself does not automatically encrypt traffic
Shadowsocks and other encrypted proxy protocolsTraffic routing through a compatible serverServer, cipher, key, and client settings must match exactly

Add a proxy server in Shadowrocket

1. Open Shadowrocket.

Open Shadowrocket on iPhone

2. Add a server. Tap the + button or the available Add Server control.

Add a proxy server in Shadowrocket

3. Choose the protocol and enter the provider's values. The exact fields change with the selected protocol. For a basic authenticated proxy, enter the address, port, username, and password exactly as supplied. Do not substitute example addresses from a tutorial.

Save the entry, then select it from the server list. If your provider supplied a configuration link or QR code, import it only after confirming its source and reviewing the nodes and rules it adds.

Connect Shadowrocket

Turn on the main connection switch. The first connection may trigger an iOS prompt asking Shadowrocket to add a VPN configuration. This is how iOS permits the app to route traffic through its network extension; it does not mean that every configured proxy is a traditional VPN.

When connected, iOS may show a VPN indicator. Open a normal web page to confirm that traffic works before changing advanced routing or DNS options.

Test server latency

Use Shadowrocket's latency-test control for the selected node. A lower result can indicate a faster response path at that moment, but it is not a complete speed or reliability test. Server load, distance, packet loss, bandwidth, and the destination service also affect performance.

Confirm that traffic uses the expected IP address

While connected, open a reputable IP-checking service and compare the displayed public IP with the address shown when Shadowrocket is off. The location database may be approximate, so a different city does not necessarily mean the connection failed.

An IP change proves only that the tested request used a different route. It does not prove that every app, DNS request, or protocol is routed the same way.

Choose a routing mode carefully

Shadowrocket can apply rules so that some destinations use the proxy and others connect directly. A global proxy mode is simpler for testing, while a rule-based setup can improve performance and keep local services direct. Importing an unknown rule set can route more or less traffic than expected, so review its source and behavior.

App-based routing may be limited by iOS and by the configuration in use. Test the actual apps that matter instead of assuming one browser test covers the entire device.

DNS leak checks and DNS settings

A DNS leak occurs when name-resolution requests use an unintended resolver and reveal destinations outside the route you expected. Switching to a global proxy rule alone does not guarantee that DNS is protected.

  1. Check the DNS settings in the active Shadowrocket configuration.
  2. Use a resolver and encrypted DNS method supported by both the app and your intended setup.
  3. Avoid mixing copied DNS rules from an unrelated provider.
  4. Reconnect after changing the configuration.
  5. Run a reputable DNS test and compare results with Shadowrocket both on and off.

If the test still shows an unexpected resolver, ask the proxy provider for configuration values specific to Shadowrocket. Do not disable certificate validation or install an unknown root certificate to make a proxy work.

Troubleshooting

  • Connection fails immediately: recheck protocol, address, port, credentials, encryption settings, and subscription status.
  • Connected but no pages load: test another server supplied by the same trusted provider and inspect DNS settings.
  • Some apps bypass the proxy: review routing rules and confirm that the app's traffic type is supported.
  • Speed is poor: compare several authorized servers and test at another time or network.
  • Configuration works on Wi-Fi but not cellular: check provider restrictions and temporarily simplify custom routing rules for diagnosis.

Use Shadowrocket only where proxy use is permitted. Keep the app and iOS updated, protect server credentials, and remove old configurations you no longer trust.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.