10 MINUTE START

Import a Clash Subscription and Verify the Connection

Follow the actual order of the client interface through importing a subscription, choosing a proxy mode, starting the connection, and verifying the result. This guide covers only the steps needed for a working first setup; advanced YAML fields, DNS, and rule syntax are covered in the configuration reference.

ROUTE MAP

First-time setup path

Switch platform: Windows macOS Android iOS Linux
BEFORE START

Before you begin

Before starting, prepare an installed Clash graphical client and either the subscription URL provided by your service provider or a YAML configuration file ready for import. A subscription URL is usually a link beginning with https://; YAML files commonly end in .yaml or .yml. You only need one of these. Do not paste a web dashboard login URL, plan page URL, or QR code screenshot as subscription text.

If the client is not installed yet, choose your platform from the client download page. Windows and macOS users can usually open the graphical interface after installation. Android and iOS will request system VPN permission the first time a connection is created; approve it when prompted. On Linux, desktop users may launch the app from the application menu, while server environments are better suited to the core and command-line configuration, which is outside this lightweight guide.

For the first setup, temporarily close other running proxies, VPNs, and network-filtering tools. Multiple programs changing the system proxy or listening on the same port can make the client appear active while the browser bypasses the current configuration. Quit older programs before opening the Clash client to reduce port and routing conflicts. If a work or campus network requires a fixed proxy, record the original settings first so they can be restored later.

Also make sure the system clock is accurate. Subscription services and some encrypted connections rely on correct time information; a large date or time-zone mismatch may appear as failed subscription updates, failed handshakes, or certificate errors. Once these checks are complete, keep the client window open and begin the next step from the configuration page.

STEP 01 · PROFILE

Import a subscription

Find the configuration or subscription page

After opening the client, go to the Configuration, Profiles, Subscriptions, or Configuration Files page. This is where the client stores loadable configurations. A new installation may show an empty list or include a local sample configuration. Do not edit the sample directly; use the add-subscription entry to create a separate item so future refreshes do not mix with local test content.

Find the add button on the configuration page. Common labels include a plus sign in the upper-right corner, Import from URL, Download Configuration, New Remote Configuration, or Import. Choose the URL option and paste the complete subscription URL into the field. If a name is required, use an easy-to-recognize purpose such as Primary or Mobile; there is no need to put the full URL in the name. Leave the update interval at its default for now; no adjustment is needed during first-time setup.

Import the configuration and confirm the result

After you click Import, Download, or Save, the client fetches the subscription and parses the YAML. Wait for a new configuration entry to appear. A successful entry usually shows its name, update time, or a refresh button; some clients switch to it immediately. If it appears but is not active, click the entry again or use Enable, Select, Set Active, or a similar action. Only an active configuration makes its policy groups and nodes available on the proxy page.

Next, open the proxy page and inspect its contents. Normally you will see several policy groups, such as node selection, auto-select, fallback, overseas services, or direct services. Names are determined by the configuration provider and may differ from these examples. If the proxy page is still empty, return to the configuration page, confirm that the active marker is on the newly imported entry, and then refresh or reload it. If the client log reports a YAML parsing error, the content was downloaded but its structure failed the core's checks. Get the subscription again, or see Frequently Asked Questions for the recommended order of checks when a configuration will not load.

Import a local YAML file

If you received a local YAML file, choose Import from File, Import File, or drag-and-drop import instead of the URL subscription option. Select the file in the configuration list after importing it. A local file does not automatically support remote subscription updates; when the service changes, you will usually need to download the file again or replace it manually. This guide does not cover YAML fields in depth. To understand the relationship between proxies, proxy-groups, and rules, see the configuration file reference.

STEP 02 · ROUTING

Choose a proxy mode

Use Rule mode for first-time setup

Once the configuration is loaded, open the Proxy, Proxies, or Mode page. Find the global mode selector, which usually offers Rule, Global, and Direct. For first-time setup, choose Rule mode. In this mode, each connection is matched against the configuration's rules from top to bottom, then sent through a proxy policy, connected directly, or blocked. Everyday web traffic and local network traffic do not have to follow the same path.

Global mode sends most traffic through one policy or node. It can help determine temporarily whether a site works through a specific node, but it is not a good default when you do not yet understand the configuration. Direct mode bypasses proxy policies and is useful for quickly checking whether a problem is related to the proxy path. These modes change traffic handling; they do not delete the subscription or alter the nodes. Switch back to Rule mode after troubleshooting.

Choose an available node for the policy group

After selecting Rule mode, inspect the policy groups. Each group is an endpoint that rules ultimately point to; it may contain individual nodes or another auto-select group. Expand the main group whose name is closest to Node Select, Proxy Select, or Proxy. If it contains Auto Select or Latency Select, choose the automatic policy first. If it contains only individual nodes, choose one marked available by the service provider.

Some clients provide a latency-test button beside each node. The result only describes the response from the client to the test target; it is not the actual speed for every website. During first-time setup, do not repeatedly chase the lowest number. A returned result and an available status are enough to continue. If every node times out, refresh the subscription first and check whether this device can open ordinary web pages. Do not change DNS, ports, and rules at the same time, or it will be difficult to identify the cause.

The configuration may also include separate policy groups for streaming media, messaging, AI services, or software downloads. For the first setup, keep their defaults and work only with the main proxy group. These subgroups often reference the main group, so choosing a node there provides an available exit for related rules. Differences between the terms policy group, node, and rule can be checked in the glossary.

Make sure the mode is not being overridden

Some clients remember the selected mode, while some configurations use overrides to lock runtime parameters. After choosing Rule mode, switch to another page and return to confirm that the interface still shows Rule. If it changes back automatically, check Overrides, included configurations, or startup settings in Settings. Temporarily disable unclear mode overrides, then select Rule mode again. Leave the main policy group pointed to an available node before starting the system connection.

STEP 03 · CONNECT

Start the connection

Confirm that the core is running

Return to the client's Home, Overview, or General page and check the core status. Some clients start the core automatically; others require Start or a service toggle. When the core is running, the page usually shows ports, the mode, or connection controls, and the tray icon may change. If it stops immediately after starting, open the Logs page and inspect the final lines. Common causes include a configuration that did not parse, a listening port already in use, or incomplete system-service permissions.

When a port is already in use, do not keep clicking Start. Quit other proxy clients, then use Task Manager or Activity Monitor to confirm that their processes have ended before restarting the current client. If it still fails, check the mixed port or HTTP and SOCKS ports in Settings. Port fields and their relationships are covered in the general fields reference; avoid changing several ports at once during first-time setup.

Enable the system proxy

Once the core is running, enable System Proxy, System Proxy, or Set as System Proxy. This directs browsers and desktop apps that follow system proxy settings to Clash's listening port. Windows usually has the client write the system proxy settings; macOS may request permission to change network settings; Android and iOS display a VPN authorization prompt; on Linux, automatic activation depends on the desktop environment and client integration.

When the system asks for permission, verify that the request comes from the client you just opened before approving it. A VPN indicator in the mobile status bar only means that the system has established a local traffic-capture channel; access to a target website still depends on the configuration and node, so verification is required. If the desktop system proxy switch turns itself off immediately, the cause is usually a permission issue, service component problem, or failure to write the system network settings. Restart the service using the client's supported authorization flow.

When to use TUN mode

The system proxy only captures programs that follow proxy settings. Some games, command-line tools, store apps, and applications with their own network stack may bypass it. TUN, virtual network adapter, or enhanced modes can capture more system traffic, but they require a virtual network device and routing permissions. For first-time setup, use the system proxy to verify a browser first. Consider TUN only when a specific app clearly ignores the system proxy.

Before enabling TUN, close other VPN tools and follow the client's instructions to install or authorize the service, then wait for the network to reconnect. If the entire system loses internet access, disable TUN immediately, confirm that the normal system proxy still works, and follow Troubleshooting in the order of permissions, routing conflicts, and DNS. Avoid repeatedly toggling the system proxy and TUN together, as this makes the active traffic path difficult to identify.

Keep the client running in the background

After you close the Clash graphical window, some platforms keep it in the tray while others exit completely. During first-time testing, do not terminate the client process. Check the system tray, menu bar, or recent apps to confirm that it is still running. If you want automatic startup, configure launch-on-boot and automatic system proxy activation only after verification succeeds, rather than locking an unfinished setup into every startup.

STEP 04 · VERIFY

Verify that it works

Check whether the client receives requests

Open a browser and refresh a familiar webpage, then switch to the client's Connections or Logs page. You should see the browser's domain, destination, matched rule, and selected policy. New connections appearing continuously mean that browser traffic has reached Clash. If the list does not change at all, check whether the system proxy is enabled, whether the browser uses its own proxy settings, and whether the client is still running in the background.

The rule information in the connection list is useful. A local website may show DIRECT, meaning it was connected directly according to the rules; a site that should use a proxy should show the main proxy group or a specific node. If every request follows the same path, first check whether the mode was accidentally set to Global or Direct. A page loading by itself does not prove the configuration is correct, because a site that already works directly cannot confirm that the proxy path is active.

Check the exit result

Next, visit a trusted IP or network-exit lookup page and note the reported region or network information. Switch to Direct mode and refresh once, then switch back to Rule mode and refresh again to compare the results. If the test request uses the selected node in Rule mode but returns to the local network exit in Direct mode, the system proxy, core, and policy group are working together. Restore Rule mode after the comparison.

If the exit result does not change but the client connection list shows the request, check which rule matched it. Some test sites may be assigned DIRECT by the configuration, which does not mean the proxy is broken. Test another target that is clearly expected to use a proxy and inspect its policy chain in the connection details. Why a rule matches a policy and how rules are evaluated from top to bottom are covered in the rule syntax reference.

Test direct and proxy paths separately

A complete check should cover both types of request: one website expected to connect directly and one expected to use the proxy. The direct site should load normally and show DIRECT or the relevant direct group in the connection record; the proxied site should show the proxy policy group and the actual node. Only when both match expectations can you confirm that Rule mode is connected and routing traffic correctly.

Run one more subscription refresh test. Return to the configuration page, click Refresh, and confirm that the update time changes while the active configuration remains selected. After the refresh, reopen the proxy page and check whether the main policy group selection was preserved. Some subscription updates rebuild policy contents; if the selected node was removed, the client may return to a default. Select an available node again; reinstalling the client is not necessary.

Save a reproducible working state

After verification, remember four key details: the active configuration name, running mode, main policy group selection, and system proxy or TUN status. If access fails later, compare these four items first; they often reveal that the configuration changed, the mode was switched, the node stopped working, or system capture was disabled. Before editing YAML, keep a copy that loads successfully so you can revert if a syntax problem appears.

QUICK FIX

Quick troubleshooting for the first connection

The checks below cover common issues that can block the main setup path. For DNS, Fake-IP, rule overrides, or complex system routing, continue with Frequently Asked Questions and the configuration reference.

What if no policy groups appear after importing the subscription?

First confirm that the new configuration is active rather than merely saved in the list. Then refresh or reload it and check the logs for a YAML parsing error. If the downloaded subscription result is a web login page or an error message, you may not be using the actual subscription URL. Return to the service page and copy the correct link again.

What if the node test works but webpages still will not open?

A successful node test only means that the test request reached the node. Confirm that the system proxy is enabled, that browser requests appear in the connection list, and that the requests match the intended policy. If browser requests are absent, the issue is system traffic capture. If requests arrive but fail, check whether the node and target website are actually reachable.

What if local websites become slower after enabling the system proxy?

First confirm that the mode is Rule rather than Global, then check whether local-site requests match DIRECT. If they still enter a proxy group in Rule mode, the configuration's rule scope or order needs adjustment. For first-time testing, try a known-good configuration; use the configuration file manual for rule customization.

What if the client says it is running but the Connections page stays empty?

Check that the system proxy switch remains enabled and that the browser has not configured its own proxy or a direct-connection exception. On desktop, also check whether another proxy program is running. On mobile, confirm that the current VPN connection still appears in the status bar and that battery-saving restrictions have not stopped the client.

TROUBLESHOOTING

Troubleshoot by symptom

Review common issues involving subscription updates, port conflicts, the system proxy, mobile permissions, and failed connections.

Open Frequently Asked Questions
CONFIG REFERENCE

Understand the configuration structure

Review general fields, DNS, proxy nodes, policy groups, rule syntax, and override and merge behavior.

Open the configuration reference