Ermaoyun (二猫云)
9.9/10From From ¥20/mo for 130 GB
Peak-hour download 210 Mbps · Packet loss 0.3%
Coupon: TIZIZHINAN20% off at checkout
Clash is a cross-platform proxy tool powered by a rule engine: domain, IP, region and rule sets decide whether each connection goes through your proxy or straight out. It speaks Shadowsocks, VMess, VLESS, Trojan, Hysteria2, TUIC and more, on Windows, macOS, Android, iOS and Linux.
Clash is just the client. You need a subscription from a provider to use it. These are the Clash-compatible providers we recommend.
From From ¥20/mo for 130 GB
Peak-hour download 210 Mbps · Packet loss 0.3%
Coupon: TIZIZHINAN20% off at checkout
From From ¥25/mo for 120 GB
Peak-hour download 195 Mbps · Packet loss 0.4%
Coupon: YUZHOU55320% off all plans at checkout
From From ¥23/mo for 148 GB
Peak-hour download 230 Mbps · Packet loss 0.2%
No coupon right now
See all provider picks and the buying guide →
Contains affiliate links; see the disclosure on the providers page.
Every platform has an actively maintained client. Click through for our pick and the installers.
Not sure which one? Compare 14 clients side by side, or run the Mihomo core on a server.
Subscriptions, rules, proxy groups, DNS and TUN work together, so you always know where each connection goes.
Route by domain, IP range, GeoIP, process or rule set — direct, proxy or reject. Local services skip the detour; everything else goes through your proxy.
Beginners import a subscription URL in one click and nodes stay up to date; power users can maintain a clean, readable YAML config by hand.
SS, VMess, VLESS, Trojan, Hysteria2, TUIC, WireGuard and more in a single client — no juggling multiple tools.
Manual select, latency test, failover and load balancing switch between nodes automatically to keep you connected.
fake-ip, DoH, DoT and per-domain resolvers cut down on DNS poisoning and leaks that send traffic down the wrong route.
A virtual network adapter captures terminals, games and desktop apps that ignore the system proxy — true system-wide proxying.
Rules are matched top to bottom and the first hit wins. Add community-maintained rule sets and you can keep local traffic direct and route the rest through your proxy — right out of the box.
rule-providers:
reject:
type: http
behavior: domain
url: https://.../reject.txt
interval: 86400
rules:
- RULE-SET,reject,REJECT # block ads
- DOMAIN-SUFFIX,openai.com,US # pin a region
- PROCESS-NAME,git,Proxy # match by process
- IP-CIDR,192.168.0.0/16,DIRECT
- GEOIP,CN,DIRECT
- MATCH,Proxy
Based on the Mihomo core; discontinued original Clash clients support only some of these.
The classic, with UDP and plugin support
UUID auth, multiple transports and TLS
XTLS Vision, Reality and multiple transports
TLS camouflage, with WS and gRPC
Stays fast on lossy, unstable networks
Low latency, with UDP relay
Standard peer, MTU and DNS settings
TLS outbound that reuses idle sessions
PSK auth and TLS obfuscation
Auth, TLS and UDP relay
Standard HTTP proxy outbound
Tunnel traffic over SSH
No command line needed — it all happens in the app.
Clash Verge Rev for Windows, macOS and Linux; FlClash for Android; Shadowrocket or Stash for iOS.
Paste the subscription URL from your provider into the Subscriptions / Profiles page, update it, and check that the node list loads.
Run a latency test and pick a node. On desktop, enable the system proxy or TUN; on mobile, allow and enable the VPN connection.
Different tasks need different routes. Rules keep them apart.
Give code hosts, package registries, container images and APIs their own rules, and stop git, npm and pip from timing out.
Put AI assistants, model consoles and API docs in their own group, and send long-lived sessions through your most stable nodes.
Reach research databases and journals worldwide while keeping campus and local resources direct.
Route meetings, shared docs and internal dashboards separately — and watch for routing conflicts with your company VPN or TUN.
Split exits by region or service, keep local services direct, and keep your account sign-in location consistent.
Use the same subscription and rule setup on desktop and phone. FlClash can even sync configs over WebDAV.
Clash is a family of rule-based proxy clients and cores. It hands your device's traffic to a rule engine, which decides whether each connection goes through a proxy, goes direct, or is rejected. Clash itself provides no proxy nodes — you get those from a provider or host your own.
A VPN usually sends all of a device's traffic through a single remote tunnel. Clash is built around rule-based routing: domain, IP, region or rule set decides where each connection goes. With TUN mode on, Clash can also capture traffic from apps that ignore the system proxy.
The desktop and Android Clash clients and the Mihomo core are all free, open-source software. Compatible iOS apps (Shadowrocket, Stash, etc.) are paid apps on App Stores outside mainland China. Proxy nodes come from third-party providers and have nothing to do with the client itself.
The original Clash core and projects like Clash for Windows are discontinued. Today's mainstream clients are built on the Mihomo (formerly Clash.Meta) core — Clash Verge Rev, FlClash and Clash Party are all actively maintained.
Clash.Meta was renamed Mihomo. It is a compatible fork of the original Clash that adds VLESS, Reality, Hysteria2, TUIC, WireGuard, rule sets, richer DNS and more.
Start with Clash Verge Rev on Windows, macOS and Linux, and FlClash on Android. On iOS, choose Shadowrocket, Stash or Quantumult X. See our client recommendations for a full comparison.
Most users import nodes, proxy groups and rules from a subscription URL. Without one, you can write the YAML by hand or use self-hosted nodes, but that's harder for beginners.
Safety depends on where your client, config and nodes come from. Only get clients from official GitHub Releases or the App Store, never import configs from unknown sources, don't expose external-controller to the internet, and keep your subscription URL private.
Pick your platform, download straight from the official release page, and follow the guide — you'll be set up in 5 minutes.