The status bar shows VPN, Home says connected, and the browser spins or fails. This combo is common, and it is the one that makes people delete the app. Do not delete it yet. A reinstall clears local permission and the local list. It will not bring a dead node back to life.
Troubleshooting does one job: split “this hop is dead” from “a rule sent the domain the wrong way.” After the split, the fix is different. The first means swap nodes or update the subscription; the second means open Config and read the rules. Mixing both at once feels like you changed everything and fixed nothing.
Confirm you are actually connected
The top of Home should say connected, not Not Connected. After you flip the switch, iOS asks for a VPN configuration. If you tapped Don’t Allow the first time, flipping the switch in the app will never take over traffic. Turn on Shadowrocket’s VPN permission in iOS Settings. You do not need to reinstall.
SERVER needs a selected node. An empty list that still shows connected usually means the switch is on with no server to use. Add a subscription or type a node first. Do not touch rules at this step.
Step 1: Swap the node
In the same subscription, pick one you just latency-tested. Prefer a result that returns a number and does not look wildly off. If the new node opens pages, the old one expired, filled up, was turned off, or this network cannot reach that host. The client is fine. Leave the rules alone for now.
If every node in the subscription fails the latency test, update the subscription first. If they all still fail, the list itself may be expired, or this network is blocking that kind of connection. Try another network: home Wi-Fi or cellular. Do not keep toggling on the same campus or hotel Wi-Fi.
If you have one typed node and no subscription, “swap node” means check Host, port, and password, and make sure Type is not Subscribe. A reversed config also looks like “connected but nothing opens,” or the connection will not stay up.
Step 2: Compare with Global Routing
If you already swapped nodes, at least one has a normal latency, and pages still fail, then change Global Routing on Home. Set it to global for a moment. Global means ignore split routing and send as much traffic as possible through the current node.
If global works and rule mode fails again, the problem is the rules: a domain sent the wrong way, an expired list, a remote config that never updated, or Test Rule showing DIRECT for that host. In Config Files, look at the config with the checkmark, update or replace it from a source you trust, then Test Rule that domain.
If global also fails, stop stacking rule files. Go back to the node, system time, and DNS. Set time to automatic. Reset DNS to the system default and try again. Some networks block common public DNS. Changing it over and over only adds noise — return to a default you can trust.
A few smaller checks
- After you swap nodes, try a private window or another browser so an old page or DNS cache does not look like “still broken.”
- Campus, hotel, and airport Wi-Fi often have a captive portal. Disconnect Shadowrocket, finish login in Safari, then connect again.
- If only some sites fail, and sites that should stay local still work, it is more likely a rule problem than a dead node.
- If only one app fails, see whether that app uses its own proxy, or a rule sent it to REJECT.
- The first connect after install may ask for VPN permission again. Until you allow it, traffic will not go where you think.
What not to do first
Do not delete Shadowrocket first. Do not switch to an unknown installer. Do not change the node, the rules, DNS, and the system proxy in one sitting. Change one class of thing at a time, so you know which step helped.
Also do not read “connected” as “every site will get faster.” In rule mode, sites that should stay local stay DIRECT. If you test with those, you will think the node is idle. Test proxy destinations with a site that should use the node; test DIRECT with a local site. Keep the two checks apart.
Finish this order before you decide
Permission on, a node in the list, and at least one normal latency — that is the base. If the base is shaky, do not tune rules. When the base is solid, cut once with global: if global works, go to Config; if global fails, stay on the node, time, DNS, and this network.
Connectivity Test on Home is a hint, not a substitute for a real page. Pass + browser fail usually means rules or cache. Fail after swapping nodes usually means this exit or this network. Do not reinstall because the test button went red once.
Office networks, campus auth Wi-Fi, and some cellular plans limit VPN types. Shadowrocket uses a VPN configuration in iOS. If the network policy blocks it, swapping nodes will not help. Switch to an unrestricted network before you decide the client itself is broken.
Write the session down: which node, global or rules, which site, which network. Next outage, compare against the note. It is faster than twenty blind toggles. The FAQ on this site is split by purchase, connection, and backup — open the matching section.
If the same node works at home and fails at work, suspect this network’s policy, not a config that suddenly died. Turn Shadowrocket off, see if ordinary pages load, then turn it back on. If the network itself is down, the client cannot help. Restore normal browsing first, then open Shadowrocket, so you do not treat an outage and a dead node as the same thing.
Categories are in FAQ: connection; the click order is in Guide: connect. If the app is not installed yet, start at the download page. This site does not provide nodes and cannot swap a line for you. It can only help you decide: change the node, or read the rules.
If you can split a node problem from a rule problem, you do not need to delete the app and start over.