A rule-based client reads its rules top to bottom for every new connection and acts on the first one that matches. A short list in the format Clash clients use:
DOMAIN-SUFFIX,target-site.com,PROXY
PROCESS-NAME,curl,PROXY
IP-CIDR,10.0.0.0/8,DIRECT,no-resolve
MATCH,DIRECT
target-site.com and its subdomains go through the group called PROXY, and so does anything curl opens. Private 10.x addresses go direct, and the final MATCH line catches the rest. Ending with MATCH,DIRECT means the proxy carries only what you named. A REJECT target drops a connection instead.
What rules can match
- Domains, exactly, by suffix or by keyword. The client knows the hostname, so it can pass it to the proxy by name and let the proxy resolve it.
- Addresses, by range (
IP-CIDR) or by country database (GEOIP). - Ports and programs, such as
DST-PORTorPROCESS-NAME. Program names must match what the operating system reports: on Linux, Python showed up aspython3.12, notpython3. - Combinations, with
ANDandOR, for example UDP to one domain only.
The order trap
An address rule needs an address. When a domain reaches an IP-CIDR or GEOIP rule written without no-resolve, the client looks the name up on your own resolver first. In a test on the Mihomo core, IP-CIDR,10.0.0.0/8,DIRECT above a domain rule sent a domain that resolved into that range straight out, and the proxy never saw it. Even when the answer fell outside the range, the lookup still went to the local resolver: a DNS leak on traffic meant for the proxy. Put domain rules first, or add no-resolve to address rules.
The same idea in other tools
A PAC file is rule-based routing for a browser, written as a JavaScript function. NO_PROXY is the smallest version: a list of exceptions to one proxy. Proxifier writes rules per application, and Clash Verge combines domain, address and program rules over a TUN mode or system proxy capture.
Common confusion
Clash clients have three modes: Rule applies the list, Global sends everything through one node you pick, and Direct sends nothing through a proxy. If a rule seems to be ignored, check that the client is in Rule mode before you debug the rule.