Rules 13-minute read

Clash Custom Rules: DOMAIN, IP-CIDR, GEOSITE Syntax and Matching Order

Need to install Clash Verge Rev on Windows 11? This beginner-friendly guide covers where to get the installer, how to run setup, what to do when Windows show…

Understand what Clash Verge Rev installs

Clash Verge Rev is a Windows graphical client built around a Clash-compatible core, commonly mihomo. The interface manages profiles, proxy groups, connection logs, system-proxy settings, and optional TUN mode; the core performs DNS handling, rule matching, and proxy connections. Installing the application does not automatically provide an active proxy subscription. You need both a working client and a configuration source, such as a subscription URL or a local Clash-compatible YAML file.

This guide uses Windows 11 as the reference environment and assumes no previous experience with proxy clients. Menu names can differ slightly between releases, especially when the bundled core or interface has been updated. The important concepts remain the same: install the desktop application, allow it to start, import a profile, select a usable proxy group, and then enable only the traffic mode you actually need.

Check Windows and account prerequisites

Clash-compatible clients often listen on local addresses such as 127.0.0.1. The exact mixed, HTTP, SOCKS, and external-controller ports depend on the release and current settings. Do not assume that a port number from another client applies to Clash Verge Rev. After installation, read the port values shown in the application’s settings and use those values when configuring a browser or another program manually.

Download and verify the Windows installer

Start from the site’s download center and choose the Windows package for Clash Verge Rev. Prefer the package format recommended for the current release, and avoid random repackaged installers, pop-up download pages, or files whose names contain unexplained extra characters. A Windows installer may be distributed as an executable file or another desktop package; the filename and installation prompts can vary between releases.

Open download center

Choose the package that matches your computer

Check What to select Why it matters
Operating system Windows macOS and Linux packages cannot be installed as Windows desktop applications.
Processor architecture Usually x64 on modern Windows 11 PCs; choose ARM64 only for a Windows ARM device when the release provides it. An incorrect architecture can prevent installation or cause the application to fail at launch.
Package type Use the installer format described on the download page. Portable and installed versions may store settings in different locations and may have different update behavior.
Release information Read the displayed version and release notes. Newer releases may update the mihomo core, TUN behavior, profile parsing, or Windows compatibility.

After downloading, open File Explorer and check the file in the Downloads folder. Windows may hide familiar extensions, so enable “View” → “Show” → “File name extensions” if you want to see whether the file ends in .exe or another format. Right-click the file, choose “Properties,” and review its size, publisher information, and the “Digital Signatures” tab when present. These checks do not prove that a file is safe by themselves, but they help identify an obviously incomplete or unrelated download.

Handle SmartScreen and antivirus prompts carefully

Windows 11 may display a Microsoft Defender SmartScreen message such as “Windows protected your PC.” This can happen when an installer is new, has limited reputation, or is not digitally signed in a way Windows recognizes. Do not bypass the warning automatically. First confirm that the filename, download location, architecture, and release information match the package you intended to obtain. If the file was downloaded from an unexpected mirror or arrived as an email attachment, cancel the installation and obtain a clean copy instead.

If the publisher is known and the file is from the expected download source, select “More info” only after completing those checks, then review the publisher and choose the option to run it if you accept the risk. If Microsoft Defender or another antivirus product quarantines the file, do not add a broad exclusion for the entire Downloads folder. Record the detection name, check the package source, and use a different verified release if the warning cannot be explained.

Install Clash Verge Rev step by step

Close other proxy clients before running the installer. If another application currently controls the Windows system proxy, both programs may compete to write the same setting. This can make a correct installation appear broken because the old client immediately restores its own proxy address.

  1. Open the downloaded installer from File Explorer. If Windows asks whether the application can make changes to the device, review the application name and select “Yes” only when the file is the package you intended to run.
  2. Read the license or introduction screen and continue. The exact wording depends on the installer framework and release.
  3. Choose the installation directory if the installer offers that option. The default directory is normally suitable for most users; avoid placing the application inside a temporary folder or a cloud-synchronized directory.
  4. Review shortcut options. A Start menu shortcut is useful for first-time setup, while a desktop shortcut is optional.
  5. Start the installation and wait for the progress bar to finish. Do not launch several copies of the installer while Windows is still writing files.
  6. When the installer offers “Launch” or “Finish,” keep the launch option enabled if you want to continue setup immediately.

Some releases install per user, while others request administrator approval and install for all users. Either arrangement can work. The important point is that the application should be installed in a stable location and be able to write its profile and log data. If the installer reports that a file is in use, close Clash Verge Rev and other Clash clients from the notification area, then run the installer again.

Complete the first-launch checks

On first launch, Windows may show a Firewall prompt. A local proxy client usually needs to accept local connections from the same computer, and TUN mode may require additional network permissions. Read the prompt’s application name and network categories. Private-network access may be reasonable on a trusted home or office network, while public-network access deserves more caution. If the prompt appears for an unexpected executable or a different application name, choose “Cancel” and investigate instead of approving it automatically.

Clash Verge Rev may display a tray icon rather than keeping a large window open. If the main window seems to disappear, look at the notification area near the clock and open the hidden-icons panel. Right-clicking the tray icon commonly provides quick controls for opening the dashboard, changing the active profile, enabling the system proxy, or quitting the client completely. “Close window” and “Exit” are not always the same action: one may hide the interface while the core continues running.

Before importing anything, open the settings and make a note of the current core, ports, and startup options. The core section should show whether mihomo is installed and available. If the core is missing, paused, or marked with an error, repair that issue before diagnosing a subscription. Also check whether “Start with Windows” is enabled. Automatic startup is convenient, but it is better to confirm a clean manual launch first.

Import a profile and enable the basic proxy mode

After confirming that the application starts, open the profile or subscription section. A subscription URL is normally added through an “Import,” “New,” or “Add profile” action. Paste the URL into the address field, give it a recognizable name such as “Primary subscription,” and save or download it. If you have a local file, use the file-import option and select the .yaml or .yml file. Keep the original URL private: anyone who possesses a subscription URL may be able to use its allocated traffic or retrieve the associated configuration.

  1. Open the profile management page and choose the add or import action.
  2. Paste the subscription URL, or select the local Clash-compatible configuration file.
  3. Wait for the download or parsing process to finish.
  4. Select the newly imported profile so that it becomes the active configuration.
  5. Open the proxies or groups page and check whether proxy groups and nodes are visible.
  6. Choose a node or an automatic selection group, then save the selection if the interface requires it.

A successful import does not prove that a node is usable. The profile may download correctly while one or more nodes fail because of expiration, unsupported protocols, an invalid server address, or a provider-side outage. If the profile loads but all nodes are missing, inspect the update log and the configuration content. A generic subscription converter may also omit features such as rule-providers, scripts, DNS settings, or mihomo-specific fields.

For a first test, use the least complicated mode. Enable the system proxy from the main window or tray menu, then open a browser that follows the Windows proxy setting. This mode usually affects applications that respect the system proxy and is easier to disable if something goes wrong. Do not enable TUN mode at the same time unless you understand why you need full-device interception.

When TUN mode is appropriate

Use TUN mode only after the profile works in ordinary system-proxy mode. TUN is useful when a desktop application does not read Windows proxy settings, when DNS requests must be handled through the configured rules, or when broader traffic interception is required. Enable it from the mode or settings page, approve the Windows permission prompt, and allow the client to install or activate its virtual network component if requested.

Do not run multiple TUN-capable proxy clients simultaneously. Two virtual adapters, competing DNS services, or duplicated routing rules can produce slow connections, loops, or a complete loss of connectivity. If TUN causes trouble, turn it off from Clash Verge Rev, restore the Windows network settings if necessary, and restart the application before testing again.

Verify the installation with simple tests

Verification should proceed from the local application outward. First confirm that the core is running and that the active profile has loaded without a fatal configuration error. Next check that at least one proxy group contains a node. Then run the client’s latency or connection test if available. A latency result only shows that a short request completed; it does not prove that every website, protocol, or large download will work.

Test Expected result If it fails
Application launch The main window or tray icon appears without a core error. Check the Windows event message, antivirus quarantine, and whether another process is using the application files.
Profile loading The profile is marked active and its groups or nodes are visible. Recheck the URL, expiration, YAML syntax, and subscription update log.
Node test At least one node returns a successful response. Try another node and inspect the core log for timeout, DNS, TLS, or authentication errors.
System proxy A compatible browser uses the selected policy after the toggle is enabled. Check the Windows proxy page and confirm that another client is not rewriting it.
TUN, if enabled A test application that ignores system proxy settings can reach the expected destinations. Check administrator permission, virtual adapter status, DNS mode, and conflicts with VPN software.

To confirm the system-proxy path, open a browser after enabling the setting and visit a normal website that you are permitted to access. Then disable the system proxy and repeat the test. The result should change only when the selected routing policy and destination make a difference; a failed page by itself does not identify whether the problem is the browser, DNS, the node, or the rule set.

For a more precise check, open the connections or logs page while loading one website once. Look for the destination domain, the matched rule, the selected policy group, and the final node. An entry showing a local source such as 127.0.0.1 generally indicates that a compatible application connected to the local proxy listener. With TUN enabled, the source and routing details may look different because traffic is intercepted through the virtual adapter.

Solve common first-day problems

When changing settings, change one item at a time and repeat the same test. Switching the profile, node, DNS mode, system proxy, and TUN mode simultaneously makes it difficult to identify the cause. Keep a short log excerpt containing the time, destination, selected policy, and error message. Avoid publishing subscription URLs, access tokens, server credentials, or complete private configurations when asking for help.

Download Clash Client Windows, macOS, and mobile versions