# Shadowrocket Proxy Setup: The iPhone Guide

> Set up a proxy in Shadowrocket on iPhone: the eight fields, the VPN profile, routing rules, sticky sessions, and the errors that break SOCKS5 on cellular.

[Home](https://quanticdata.io/)/[Blog](https://quanticdata.io/blog/)/Shadowrocket Proxy Setup: The iPhone Guide

# Shadowrocket Proxy Setup: The iPhone Guide

ProxiesSep 12, 2026·9 min read·By [Aldo Morese](https://quanticdata.io/about/), founder of QuanticData

Shadowrocket sends each connection down one of three paths: proxy, direct or rejected

On this page [What Shadowrocket actually is](/blog/shadowrocket-proxy-setup/#what-shadowrocket-actually-is) [What you need before you open the app](/blog/shadowrocket-proxy-setup/#what-you-need-before-you-open-the-app) [Adding the server, step by step](/blog/shadowrocket-proxy-setup/#adding-the-server-step-by-step) [Verify the exit, and know what a good one looks like](/blog/shadowrocket-proxy-setup/#verify-the-exit-and-know-what-a-good-one-looks-like) [Why your IP keeps changing, and how to stop it](/blog/shadowrocket-proxy-setup/#why-your-ip-keeps-changing-and-how-to-stop-it) [Global Routing and the rules that justify the app](/blog/shadowrocket-proxy-setup/#global-routing-and-the-rules-that-justify-the-app) [When it does not connect](/blog/shadowrocket-proxy-setup/#when-it-does-not-connect) [What it costs to run a phone through a proxy](/blog/shadowrocket-proxy-setup/#what-it-costs-to-run-a-phone-through-a-proxy)

Shadowrocket is a rule-based proxy client for iPhone and iPad, not a VPN subscription. You supply the proxy; the app decides, connection by connection, what goes through it. Adding a server takes four values and about two minutes. The routing rules are the part that decides whether the app was worth buying.

## What Shadowrocket actually is

The App Store listing describes it plainly: a rule based proxy utility client that captures all HTTP, HTTPS and TCP traffic from any application on the device and redirects it to a proxy server. It is published by Shadow Launch Technology Limited, costs $2.99, needs iOS 13 or later, and carries a 4.5 rating over roughly 12,000 ratings. The documented feature set is what separates it from the proxy fields buried in iOS Settings: rules by domain match, domain suffix, domain keyword, CIDR range and GeoIP lookup, rule files imported from a URL or iCloud Drive, local DNS mapping, per-connection traffic accounting, and DNS over HTTPS, TLS or QUIC.

Two things it is not. It is not an encrypted tunnel to a provider you subscribe to, because the security of the hop depends entirely on the proxy you point it at. And despite the prompt you will see in a moment, it is not a VPN app either. iOS only lets an app capture another app's traffic through the Network Extension framework, and that framework requires an installed VPN profile. The profile is the delivery mechanism, not the product.

## What you need before you open the app

Four values, all of which come from your proxy dashboard:

- **Address**, the gateway hostname of your provider.

- **Port**, which usually differs between the HTTP and the SOCKS5 entry point.

- **User**, which on residential and mobile networks often carries the targeting parameters as well.

- **Password**.

Pick the network before the protocol. A phone is a browsing client, so [residential exits](https://quanticdata.io/residential-proxies/) behave best on consumer sites, and [mobile exits](https://quanticdata.io/mobile-proxies/) are the right choice when the target expects carrier traffic. Datacenter ranges are cheaper and faster but are recognised as datacenter ranges by exactly the apps people install Shadowrocket to reach. On protocol, HTTP is the safer default on iOS; [SOCKS5](https://quanticdata.io/socks5-proxies/) carries anything TCP rather than only web traffic, which matters for messaging apps, and it is also the protocol that fails in the most confusing ways, as the troubleshooting section below explains.

One warning that costs people an afternoon: do not plan on IP whitelist authentication. A phone moves between Wi-Fi and cellular and its public address changes with it, so an allowlist entry goes stale the moment you leave the house. Use username and password authentication and keep the allowlist for fixed machines.

## Adding the server, step by step

1. Install Shadowrocket from the App Store and open it. The main screen shows a connection toggle, a Global Routing selector and the list of servers, which starts empty.

2. Tap the plus icon, or **Add Server**.

3. Set **Type** to HTTP, HTTPS or SOCKS5, matching the port you were given.

4. Fill in **Address** and **Port**.

5. Fill in **User** and **Password**. On a residential or mobile plan the targeting parameters usually live inside the username, appended to it with dashes, so paste it exactly as the dashboard prints it.

6. Tap **Save**. The server appears in the list with a latency figure once you test it.

7. Set **Global Routing** to **Proxy** for a first test, so that nothing is decided by rules yet.

8. Flip the connection toggle. iOS asks permission to add a VPN configuration: allow it and confirm with your passcode or Face ID. This happens once, and it is the Network Extension profile rather than a subscription to anything.

If the toggle flips back by itself, the app never established the tunnel. That is a proxy failure, not an iOS one, and the causes are below.

## Verify the exit, and know what a good one looks like

Open a browser and load an IP echo. The address it reports should be the proxy, and the network behind it should look like a household rather than a server farm. To show what that means we queried an IP echo through country-targeted residential exits on 12 September 2026, using the QuanticData MCP server, and recorded what the site saw:

| Country requested | Exit seen by the site | Network behind the address |
| --- | --- | --- |
| United States | Orlando, Florida | AS33363 Charter Communications |
| United Kingdom | Harpenden, England | AS13285 TalkTalk Communications |
| Japan | Tokyo | AS17676 SoftBank |
| Brazil | Sumare, Sao Paulo | AS28649 Desktop Sigmanet |

All four landed in the country requested, and all four resolved to consumer broadband operators with residential reverse-DNS names. That is the shape you are paying for: if your echo instead returns a hosting company, you are on a datacenter range, and the sites that care will treat you accordingly. The [proxy tester](https://quanticdata.io/tools/proxy-tester/) runs the same check from a desktop browser when you want to confirm credentials before typing them into a phone.

## Why your IP keeps changing, and how to stop it

A rotating endpoint gives you a new exit per connection. We sent four consecutive requests to the same echo through a rotating United States endpoint, roughly twenty seconds apart in total, and got four different households: Charter in Orlando, Comcast in Fresno, Cablevision in New York, Verizon in Clifton, New Jersey. Four requests, four addresses, four operators.

That behaviour is ideal for collection and fatal for a session. If an app holds a login, a cart or a one-time code, an address that changes mid-flow reads as account takeover and you will be logged out or challenged. The fix is a sticky session, requested through the username with a session identifier your provider documents, so the same exit is held for a set number of minutes. Rotating and sticky are the same endpoint with a different username; the difference between [rotating and sticky behaviour](https://quanticdata.io/rotating-proxies/) is a decision you make per use case, not per plan.

## Global Routing and the rules that justify the app

Global Routing has three settings. **Proxy** sends everything through the exit. **Direct** sends nothing. **Config** hands each connection to your rule list, which is the only mode that makes the purchase worthwhile. Rules are evaluated top to bottom, first match wins, and the last line decides everything that matched nothing.

The configuration is a plain text file you can write on a computer and import from a URL or iCloud Drive. A minimal, readable skeleton looks like this:

```
[General]
bypass-system = true
skip-proxy = 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12, localhost, *.local
dns-server = 1.1.1.1, 8.8.8.8
ipv6 = false

[Rule]
DOMAIN-SUFFIX,icloud.com,DIRECT
DOMAIN-SUFFIX,apple.com,DIRECT
IP-CIDR,192.168.0.0/16,DIRECT
DOMAIN-KEYWORD,analytics,REJECT
DOMAIN-SUFFIX,example-target.com,PROXY
GEOIP,IT,DIRECT
FINAL,DIRECT
```

Read it as a policy rather than as code. Apple services and the local network go out untouched, so push notifications and AirPlay keep working. Anything whose hostname contains a tracking keyword is dropped before it leaves the device, which is also the cheapest possible optimisation because rejected bytes are never billed. One target domain is proxied. Addresses that GeoIP places in your own country stay direct. The final line then chooses the default posture, and this is the line that decides your bill: `FINAL,DIRECT` means only what you named goes through the proxy, while `FINAL,PROXY` means everything does, including background chatter from apps you were not using.

Two subtleties worth knowing before your rules misbehave. A rule that matches on IP forces a DNS lookup unless you append `no-resolve`, which is why published rule sets carry that suffix on their IP-CIDR lines. And a hostname on a shared CDN is not owned by the site that uses it, so a broad REJECT on a CDN domain will silently break images and scripts on pages you wanted to keep.

## When it does not connect

The failures are few and each has a signature.

- **The toggle flips back immediately.** The tunnel never came up. Check the address and port pair first, then whether another VPN or content blocker already holds the Network Extension slot, since only one can be active.

- **Connected, but every page times out.** Usually authentication. A proxy that rejects your credentials answers with 407 rather than a friendly message, and the app shows you nothing at all; our [407 guide](https://quanticdata.io/blog/how-to-fix-407-proxy-authentication-required/) walks the same failure on a desktop client where the error text is visible.

- **HTTP works and SOCKS5 does not.** This is the most reported Shadowrocket-specific problem. Providers document a workaround in the server settings: change the connection method from *auto* to *random* and reconnect. Where a firewall is actively fingerprinting protocols, plain SOCKS5 may be blocked outright and an encrypted transport is the only reliable answer.

- **It works on Wi-Fi and dies on cellular.** Almost always IP allowlist authentication that no longer matches your carrier address. Switch that server to username and password.

- **The exit is right but one app still sees your real location.** That app is probably resolving names or geolocating outside the proxied path. Check your DNS setting and confirm the app's domains actually match a PROXY rule rather than falling through to a DIRECT final line.

## What it costs to run a phone through a proxy

Metered proxies bill bytes, and a phone in `FINAL,PROXY` mode sends far more of them than you would guess, because a single page drags dozens of subresources behind it, as we measured in [a recent teardown of browser page loads](https://quanticdata.io/blog/playwright-proxy/). Residential traffic starts at $0.80 per GB and mobile at $2.30 per GB, so the difference between routing everything and routing one app is the difference between a plan that lasts a month and one that lasts a weekend. If you are unsure which plan size to buy, [the sizing walkthrough](https://quanticdata.io/blog/how-much-proxy-data-do-i-need/) converts real workloads into gigabytes.

The practical setting for most people is `FINAL,DIRECT` with a short list of PROXY rules for the domains that actually need a different exit, plus a handful of REJECT lines for telemetry. You get the exit where it matters, your bank app keeps working, and the meter moves slowly.

### Sources & further reading

- [Shadowrocket on the App Store (developer, price, requirements, feature list)](https://apps.apple.com/us/app/shadowrocket/id932747118)

- [Apple — Network Extension framework](https://developer.apple.com/documentation/networkextension)

- [A published Shadowrocket configuration file (rule syntax and sections)](https://gist.github.com/wgzhao/b341dbbede356c38be4407c439e95b5c)

- IPRoyal — Shadowrocket integration, including the SOCKS5 connection-method workaround

- Decodo — Shadowrocket proxy setup guide

## FAQ

Quick answers on shadowrocket proxy setup.

[Something else? Ask us →](mailto:hello@quanticdata.io)

### Is Shadowrocket a VPN?

No. It installs a VPN profile because iOS only allows an app to capture other apps traffic through the Network Extension framework, but it provides no network of its own. It routes your connections to a proxy you supply, so the privacy and the exit location come from that proxy, not from the app.

### Does Shadowrocket work on Android, Windows or Mac?

The App Store listing covers iPhone, iPad, iPod touch, Mac and Apple TV. It is not an Android or Windows application, and guides that show an Android screen are using a different client with a similar interface. On a desktop you would use the system proxy settings or a per-application setting instead.

### Which proxy type should I pick for an iPhone?

Residential for ordinary browsing and consumer apps, mobile when the target expects carrier traffic, and datacenter only for speed on targets that do not inspect the range. On protocol, HTTP is the most reliable default on iOS and SOCKS5 is the right pick when you need to carry traffic that is not web traffic.

### Why does my IP change every few seconds in Shadowrocket?

You are on a rotating endpoint, which issues a new exit per connection. Four consecutive requests through one rotating United States endpoint on 12 September 2026 returned four different addresses on four different operators. Request a sticky session through the username if you need the address to hold.

### Can I use an IP whitelist instead of a username and password?

On a phone, not reliably. The public address changes when you move between Wi-Fi networks and cellular, so an allowlist entry stops matching without warning. Username and password authentication travels with the configuration and keeps working wherever the device is.

### How do I stop Shadowrocket from eating my proxy data?

Switch Global Routing to Config and end your rule list with a direct default, so only the domains you name are proxied. Add REJECT rules for telemetry hostnames, because traffic dropped on the device is never billed, and keep Apple services and the local network on direct rules so notifications keep working.

## Proxies that hold up on a phone

Residential and mobile exits with country targeting, HTTP and SOCKS5 on the same plan, sticky sessions when you need the address to stay put. Every account gets $2 of free API usage each month.

[Start free — $2/month included](https://quanticdata.io/signup/)[Explore Residential Proxies from $0.80/GB](https://quanticdata.io/residential-proxies/)

## Related reading

[Proxies curl Proxy: Setup, Auth, SOCKS5 and Errors One flag sets a proxy in curl. The rest of the work is authentication, SOCKS5 versus SOCKS5h, HTTPS tunnelling, and reading the exit code when it fails. Read →](https://quanticdata.io/blog/how-to-use-a-proxy-with-curl/) [Proxies httpx Proxy: Setup, Auth and the proxies= Fix The httpx proxy argument changed name, and most tutorials still teach the removed one. A version-by-version matrix, the exact exception text, and what the proxy sees on the wire. Read →](https://quanticdata.io/blog/httpx-proxy/) [Proxies Playwright Proxy: Setup, Auth and Bandwidth Playwright takes a proxy as an object, not a URL, and a browser pays for the whole page rather than the HTML. Per-context exits, the auth rules, the net errors, and measured bytes for seven real pages. Read →](https://quanticdata.io/blog/playwright-proxy/)

## Also on this site

Quantic**Data**

Residential proxies & web data APIs for AI.

#### Proxies

- [Residential Basic](https://quanticdata.io/residential-proxies/#basic)

- [Residential Premium](https://quanticdata.io/residential-proxies/#plans)

- [Cheap Residential](https://quanticdata.io/cheap-residential-proxies/)

- [Mobile Proxies](https://quanticdata.io/mobile-proxies/)

- [Datacenter Proxies](https://quanticdata.io/datacenter-proxies/)

- [ISP Proxies](https://quanticdata.io/isp-proxies/)

- [Web Unlocker proxy](https://quanticdata.io/web-unlocker/)

- [Enterprise solutions](https://quanticdata.io/enterprise-solutions/)

- [Rotating Proxies](https://quanticdata.io/rotating-proxies/)

- [Sneaker Proxies](https://quanticdata.io/sneaker-proxies/)

- [SOCKS5 Proxies](https://quanticdata.io/socks5-proxies/)

- [IPv6 Proxies](https://quanticdata.io/ipv6-proxies/)

- [Proxy locations](https://quanticdata.io/proxies/)

#### Data APIs

- [MCP Server](https://quanticdata.io/mcp-server/)

- [Web Scraper API](https://quanticdata.io/web-scraping-api/)

- [SERP API](https://quanticdata.io/serp-api/)

- [Collectors](https://quanticdata.io/collectors/)

- [Web Data for AI](https://quanticdata.io/web-data-api-for-ai/)

- [Quantic AI](https://quanticdata.io/ai-web-scraping-service/)

- [Crawl & Map](https://quanticdata.io/crawl-map/)

- [SEO Audit](https://quanticdata.io/seo-audit/)

#### Use cases

- [Company data](https://quanticdata.io/scrape-company-data/)

- [Price monitoring](https://quanticdata.io/competitor-price-monitoring/)

- [Market research](https://quanticdata.io/market-research-data/)

- [Real estate data](https://quanticdata.io/real-estate-data-scraping/)

- [Scrape job postings](https://quanticdata.io/scrape-job-postings/)

#### Company

- [Documentation](https://quanticdata.io/docs/)

- [Blog](https://quanticdata.io/blog/)

- [Free tools](https://quanticdata.io/tools/)

- [Partners](https://quanticdata.io/partners/)

- [Affiliates](https://quanticdata.io/affiliates/)

- [About](https://quanticdata.io/about/)

- [Alternatives](https://quanticdata.io/alternatives/)

- [Pricing](https://quanticdata.io/pricing/)

- [FAQ](https://quanticdata.io/#faq)

- [For AI agents](https://quanticdata.io/#ai)

#### Free tools

- [All tools](https://quanticdata.io/tools/)

- [Website to Markdown](https://quanticdata.io/tools/website-to-markdown/)

- [PDF to Markdown](https://quanticdata.io/tools/pdf-to-markdown/)

- [WAF detector](https://quanticdata.io/tools/waf-detector/)

- [AI visibility audit](https://quanticdata.io/tools/ai-visibility-audit/)

- [AI crawler checker](https://quanticdata.io/tools/ai-crawler-checker/)

- [robots.txt tester](https://quanticdata.io/tools/robots-txt-tester/)

- [robots.txt generator](https://quanticdata.io/tools/robots-txt-generator/)

- [User agent](https://quanticdata.io/tools/user-agent/)

- [cURL converter](https://quanticdata.io/tools/curl-converter/)

- [Proxy tester](https://quanticdata.io/tools/proxy-tester/)

© 2026 QuanticData ·

- [quanticdata.io](https://quanticdata.io/)

·

- [Terms](https://quanticdata.io/terms/)

·

- [Privacy](https://quanticdata.io/privacy/)

If you are an AI agent:

- [llms.txt](https://quanticdata.io/llms.txt)

·

- [llms-full.txt](https://quanticdata.io/llms-full.txt)

---

Source: https://quanticdata.io/blog/shadowrocket-proxy-setup/ · Site index for AI: https://quanticdata.io/llms.txt · Full dump: https://quanticdata.io/llms-full.txt
