PrologueGetting Started · QUICKSTART

Clash Beginner's Guide: Import a Subscription & Verify Your Connection in 4 Steps

This guide is for first-time Clash users. Follow four steps in order: import your subscription, choose a proxy mode, turn on the connection, and verify it's working — about 10 minutes total. We use three concepts shared across all Clash clients — subscription, mode, and system proxy — to describe every action, with UI differences called out in sidebars. For rule syntax and protocol details, see the Handbook and FAQ pages.

Note · UI Differences Between Clients

Clash clients (Clash Plus, Clash Verge Rev, FlClash, and others) all look different, but they share the same core concepts: subscription (profile), proxy mode, and the system proxy switch. This guide uses those three terms consistently, with each client's typical menu location noted inline. Desktop and mobile (Android / iOS) connect slightly differently — that's covered separately in Step Ⅲ. Once you've done all four steps on one platform, the same logic carries over to the others.

Before You Start: Two Things You'll Need

1. Install a Client

If you haven't installed a client yet, head to the Downloads page and grab one for your platform. Clash Plus is the top pick everywhere, with versions for Windows, macOS, Android, and iOS. You only need to set up one platform to begin — desktop or mobile.

Go to Downloads →

2. Get a Subscription Link

Your subscription link comes from your proxy service provider — usually a long URL starting with http, found in your account dashboard. It carries all your node data and works like login credentials, so keep it private and never share or post it publicly.

~10 minutes total setup time · 4 steps: Import · Mode · Connect · Verify · Works with Clash Plus / Verge Rev / FlClash and similar clients · You'll need a client installed + a subscription link
Step ⅠImport Subscription · IMPORT

Import Your Subscription: Load the Node List Into Your Client

The subscription link is your sync channel to the node list. Import it and select it — every later step depends on this one.

A subscription is the sync mechanism between your client and your provider: one link maps to one node list, and the client pulls it on demand so your local nodes stay in sync with your provider. Importing it is the first step of setup.

Open your client and go to subscription management. It's called "Profiles" or "Subscription" in Clash Plus, sits under "Subscription" in the left sidebar in Clash Verge Rev, and lives under "Profiles" (sometimes just labeled that way) in FlClash. Tap "New", "Add", or the + button in a corner — the form usually just asks for a name and a link. The name is just a label to tell subscriptions apart; paste the link you copied earlier into the subscription URL field, and double-check there's no stray space or line break at either end.

After saving, go back to the subscription list, find the entry you just added, and tap "Update" (some clients show a circular refresh icon instead). The client sends a request to the subscription URL and downloads the node list. Once it's done, the entry shows the node count, traffic info, and last update time — that's your sign the import succeeded.

One easy-to-miss step: set this subscription as your active profile. Most clients require tapping the subscription entry itself (or a radio button on it) to select it — only then does the main node list switch over. Import without selecting it, and the main screen stays on your old profile or shows nothing at all — this is the single most common snag for first-timers.

Note · Subscription Update Fails

Update failures usually come down to one of three things: the link has expired or been reset by your provider, your current network can't reach the subscription URL directly, or the link got copied incompletely. Try pasting the link straight into your browser's address bar — if it downloads something, the link itself works and the issue is on the client or network side. For deeper troubleshooting, see the FAQ page.

Step ⅡChoose Proxy Mode · MODE

Choose a Proxy Mode: Rule, Global, or Direct

These three modes decide where every request goes. For daily use, pick Rule mode and select a node with normal latency in a proxy group.

Proxy mode decides how your client handles every network request — what goes direct, what goes through the proxy, what gets blocked. Here's what each mode does; you can switch anytime.

Rule ModeRule

Matches every request against the built-in rule set: domestic (mainland China) sites go direct, overseas sites route through the proxy, and ad/tracking domains get blocked by rule. Recommended for everyday use.

Global ModeGlobal

Every request routes through the proxy node, no exceptions. Useful for troubleshooting routing issues or when you temporarily need a single unified exit — not meant to be left on permanently.

Direct ModeDirect

No request goes through the proxy — effectively pauses proxying entirely. Handy for A/B comparisons, or to temporarily turn off proxying without closing the client.

The mode switch is usually front and center: at the top of the home screen in Clash Plus, at the top of the Proxies page in Clash Verge Rev, and in the mode dropdown on the main screen in FlClash. New users can just pick Rule mode: domestic sites stay fast via direct connection, overseas sites go through the proxy, and ads/trackers get blocked automatically.

Mode alone isn't enough — you also need to pick a node. Go to the Proxies page and you'll see one or more proxy groups, commonly named something like "Proxy" or "Auto". A proxy group is an internal routing bucket: once a rule matches, the request gets handed to that group, and whichever node is currently selected in it handles the actual traffic. Just tap a node with normal latency in the main group — or switch to "Auto" and let the client pick based on latency automatically. Most node cards have a speed-test button; skip any node that's timing out or showing high latency.

The routing logic behind Rule mode — rules matched top to bottom, first match wins, everything else falls to MATCH — is more advanced territory this guide won't dig into. If you need custom rules or want to understand match order, check the relevant section on the Handbook page.

Step ⅢTurn On Connection · CONNECT

Turn On the Connection: Route System Traffic Through the Client

Flip the system proxy switch on desktop, or grant VPN permission on mobile. Once you see the connected indicator, traffic follows your chosen mode and node.

Even with everything set up, the client won't take over any traffic on its own — you need to turn the connection on explicitly. Desktop and mobile work differently, covered separately below; just read the section for whichever platform you're using, since the two don't affect each other.

Desktop: System Proxy and TUN

Windows and macOS clients both have a "System Proxy" switch on the main screen. Turn it on, and the client writes its own address into your OS proxy settings — your browser and most apps then route through the client immediately; turn it off and the system settings revert automatically. This is the go-to connection method, works instantly, and is where you should start.

A handful of apps ignore system proxy settings — typically some command-line tools and game clients. If you need those to be proxied too, switch to TUN mode instead: it creates a virtual network adapter and takes over all traffic at the network layer, independent of whether an app supports proxies at all. TUN needs admin permission the first time you enable it — Windows shows a UAC prompt, macOS asks for your login password — and only once. System proxy is plenty for everyday browsing; save TUN for when you actually need it.

Mobile: VPN Permission

On Android and iOS, the client takes over traffic by acting as a VPN service. Tap Connect on the main screen, and the first time, your system will show a VPN permission prompt — tap Allow. On iOS, if you're asked to add a VPN configuration, allow that too. A VPN icon appearing in the status bar means the connection is live, and you won't be asked to authorize again after that.

A successful connection looks the same across platforms: the client's main screen shows it's running, the desktop tray icon changes color, and mobile shows a VPN badge in the status bar. Once you see that, traffic is already routing according to your chosen mode and node — time to move on to verification.

Note · Launch on Startup

If you want the client to launch automatically and reconnect on boot, look for a "Launch on Startup" option in Settings — some clients also offer "Silent Start" (launches without opening the main window). For exact locations and gotchas per client, see the Setup & Configuration section on the FAQ page.

Step ⅣVerify It Works · VERIFY

Verify It's Working: Confirm Traffic Is Actually Going Through the Proxy

Run one IP check and one connections-panel check to confirm both the exit and rule matching look right — then you're good to go for daily use.

Once connected, verify right away that routing is working as expected — don't wait until something breaks to start troubleshooting. There are two layers to check: exit verification (IP) and rule verification (connections panel).

Exit Verification: Check Your Current IP

Open any IP lookup site (like ip.sb or ipinfo.io) in your browser — the location shown should match your chosen node's region, not your actual ISP location. Then turn off the system proxy (or disconnect on mobile) and refresh the same page — the location should revert to your real one. Comparing on vs. off confirms the proxy is actually handling your traffic.

Rule Verification: Check the Connections Panel

The Connections panel in your client lists every request in real time: the domain, which rule matched it, and which proxy group/node it was routed to. In Rule mode, visit a few domestic and a few overseas sites and check the panel: domestic sites should show DIRECT, overseas sites should land on a proxy group. If matches don't look right, your rule set is probably outdated — update your subscription and try again.

CheckActionExpected Result
Exit IPOpen an IP lookup site in your browserLocation shown matches your node's region
A/B comparisonTurn off system proxy and refresh the lookup pageLocation reverts to your actual ISP
Rule matchingCheck the client's Connections panelDomestic sites show DIRECT, overseas sites use a proxy group
Node availabilityRun a latency test on the Proxies pageCurrent node shows normal latency, not a timeout

If verification fails, check three things in order: whether the system proxy switch is still on, whether you're in Rule or Global mode, and whether your selected node is timing out on the latency test. If all three check out and it's still not working — or you're hitting something trickier like DNS leaks or a specific app bypassing the proxy — that's covered in the Troubleshooting section of the FAQ page, which we won't repeat here.

EpilogueWhat's Next · NEXT

Ongoing Maintenance & Further Reading

Once you've done these four steps, your client is ready for regular use — day-to-day, there's really just two small things left: updating your subscription and switching nodes.

First, update your subscription regularly. Providers add and remove nodes on their end, and tapping Update in your subscription list keeps you in sync; most clients let you set an auto-update interval, so you only have to configure it once. Second, switch nodes whenever one slows down or drops: run a fresh speed test on the Proxies page, pick a node with normal latency, or just let Auto-select handle it.

This guide only covers the basics to get you up and running — deeper topics have their own pages: proxy protocol fundamentals and how the core families relate to each other are on the Handbook page; subscription conversion, launch-on-startup, DNS leaks, and other fine details are on the FAQ page; and if you switch devices or reinstall your OS, head back to the Downloads page to grab the right package for your platform.