iPhone VPN Setup Guide: Import Subscriptions in Shadowrocket

Learn how to set up a VPN on iPhone with Shadowrocket from start to finish. Follow clear steps to install the app, add your subscription URL, select a server, verify the connection, and handle the most common setup problems.

Setting up a VPN on an iPhone with Shadowrocket is straightforward once you understand the relationship between the subscription URL, the imported server profiles, the selected node, and the iOS permission prompt. Shadowrocket is a compatible iOS network tool that can manage proxy and VPN-style configurations, but it does not provide servers by itself. You need a valid subscription from a service provider, install the app through an official and trustworthy channel, import the subscription, choose a suitable profile, and verify that traffic is using the expected connection.

This guide explains the complete workflow from preparation to troubleshooting. It also clarifies which settings should normally remain unchanged, how to protect a subscription URL, why a profile may appear imported but still fail to connect, and how to test the result without relying only on a green “Connected” status. Menu names can vary slightly between Shadowrocket versions and iOS releases, but the underlying process remains similar.

Prepare Before Installing Shadowrocket

Before opening the App Store, confirm that you have three things ready: an iPhone with a working internet connection, access to a legitimate Shadowrocket download source, and a subscription URL supplied by your VPN or proxy provider. A subscription URL normally looks like a web address rather than a username and password. It may return a collection of server profiles in a format that Shadowrocket can recognize and periodically update.

Do not copy a subscription URL from an unknown public post or paste it into an untrusted converter. The URL can function like an access credential. Anyone who obtains it may be able to retrieve your current server configuration or consume the traffic associated with your account. Treat it in the same way you would treat a private account link: do not publish it in screenshots, send it through public comments, or store it in a note that is synchronized to an account you do not control.

90+

Countries covered

200+

Routes available

5

Common protocol families

iOS

Supported platform

For a QaVPN subscription, the supported platform list includes iOS as well as Windows, macOS, Android, and Linux. The service provides 90+ countries and 200+ routes, but the actual profiles shown in Shadowrocket depend on your account, plan, provider configuration, and the current subscription response. A large location list does not mean every route will perform identically on every mobile network, so plan to test more than one suitable profile.

Also decide whether you need a full-device connection or selective routing. A full-device configuration sends eligible iPhone traffic through the selected profile, while rule-based routing can send some domains directly and other traffic through the proxy. Full-device mode is easier for a first test. Rule-based mode is more flexible, but an incorrect rule can make an app appear broken even when the proxy itself is working.

Install and Review Shadowrocket

Install Shadowrocket only from the official App Store listing available in your Apple account region. Confirm the publisher information, app identity, and current compatibility before downloading. Avoid unofficial modified packages, configuration profiles that ask for unnecessary permissions, or installation instructions that require disabling normal iOS security protections. If the app is unavailable in your region, do not use an unknown download site as a substitute; first confirm whether your provider offers an official iOS client or another compatible client.

After installation, open Shadowrocket and review its basic sections. Most versions expose a profile or configuration list, a subscription management area, a server list, routing options, and a connection switch. The first connection attempt normally causes iOS to display a system prompt asking permission to add VPN configurations. Read the prompt carefully and approve it only when you started the action yourself and recognize the app that requested it.

Shadowrocket can work with several proxy or tunnel formats, including Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and, in compatible configurations, WireGuard. These names describe different protocol or transport implementations; they are not interchangeable password fields. A subscription usually contains the required server address, port, authentication information, encryption or transport settings, and optional routing metadata. Manually changing one field without understanding the profile can invalidate the configuration.

Import the Subscription URL

After Shadowrocket is installed, copy the subscription URL from your provider’s account panel or delivery message. Copy the complete address from the beginning to the end. Do not add quotation marks, spaces, line breaks, or explanatory text. If the provider gives more than one URL, check the label before importing because different links may represent different formats, regions, or update channels.

  1. Open Shadowrocket and go to its subscription or configuration management area.
  2. Choose the option for adding a subscription, remote configuration, or subscription URL.
  3. Paste the complete URL into the URL field.
  4. Give the subscription a recognizable local name, such as the provider name and device purpose.
  5. Save the entry, then use the update or refresh action to retrieve the profiles.
  6. Open the imported profile list and confirm that server entries are visible.

The exact button may be called Add, Subscribe, Remote, or Import depending on the app version. The important distinction is between importing a remote subscription and adding one individual server manually. A subscription is designed to be updated from its source, while a manually entered server is usually a single static configuration. If your provider specifically supplied a subscription link, use the subscription function rather than pasting the link into a server address field.

If the app reports that the URL is invalid, first check whether the link was truncated by the message app or browser. Some providers display a long URL that wraps across multiple lines, but the copied value should remain one continuous address. Next, check whether the link has expired, whether your account is active, and whether the subscription endpoint requires the current account session. If the link opens a web page asking you to log in, it may not be the direct subscription URL that Shadowrocket expects.

Once the profiles appear, avoid editing every field immediately. Subscription entries can contain protocol-specific values that are easy to damage. Make a backup or note of the original subscription name and update address before experimenting. If a provider offers separate links for different client families, select the format intended for Shadowrocket or for compatible proxy clients rather than a format designed only for a native desktop application.

Select a Server and Connect

With the subscription imported, return to the main screen and inspect the available profiles. Names may identify a country, city, route type, protocol, or load category. Select a profile that matches your current purpose and network conditions. A nearby location is often a sensible starting point for general browsing, but distance alone does not determine quality. Congestion, upstream routing, mobile carrier policy, transport behavior, and server load can all affect the result.

Begin with a normal profile rather than changing advanced parameters. If several entries are available, test them one at a time and record which one provides stable access for the apps you actually use. Do not start two VPN clients simultaneously. Running Shadowrocket together with another VPN, a system-wide proxy utility, or a security application that installs its own tunnel can create competing routes and make troubleshooting much harder.

  1. Tap the server or node selector and choose one imported profile.
  2. Return to the main screen and enable the connection switch.
  3. Read the iOS permission prompt and approve the VPN configuration if it matches your intended action.
  4. Wait for the connection state to change, then keep Shadowrocket active while performing the first test.
  5. Open a browser or another low-risk app and verify normal access before testing more demanding services.

Shadowrocket may offer modes such as configuration, global proxy, or rule-based routing. Configuration mode generally uses the rules contained in the selected profile. Global mode sends a broader range of eligible traffic through the selected proxy. Rule-based mode depends on the quality of the rule set: a domain can be routed directly, through the proxy, or rejected according to the matching rule. If you are diagnosing a first connection, use the simplest mode available, then introduce customized rules only after the basic path works.

Practical conclusion: Import the provider’s profile first, test one node in a simple routing mode, and postpone advanced rule edits until you have confirmed that the basic connection works.

Verify the iPhone Connection

A connected indicator is useful, but it is not a complete verification. A profile can connect successfully while a particular app bypasses the proxy, a domain is routed directly by policy, or DNS behavior differs from what you expected. Verification should therefore include both the iPhone system state and the behavior of the applications you intend to use.

Start by checking whether iOS shows the VPN indicator or an active VPN state in Settings. Then open a browser and visit a reputable IP-checking page. The reported public IP and approximate exit location should correspond to the selected profile rather than your ordinary network. Location databases are not perfectly precise, so a city mismatch is not always a failure; compare the displayed country, network provider information, and consistency across more than one check.

Next, test a few normal actions that represent your real usage. Load an ordinary webpage, sign in to a service only if necessary, send a small message in a permitted application, and switch between Wi-Fi and mobile data if that is part of your routine. Observe whether the connection remains available after the screen locks and unlocks. iOS may suspend or re-establish network activity depending on the app, tunnel type, battery settings, and network transition.

DNS results can also provide useful clues. If webpages open but some domain names fail, the issue may involve DNS handling, an incorrect rule, or an application-specific connection method. If only one app fails while the browser and other apps work, inspect the routing mode and the app’s own network settings before replacing the entire subscription. Some applications use their own encrypted transport or enforce regional policies that a proxy cannot change.

Privacy verification requires a separate review. A proxy connection can protect traffic between your device and the selected service, but it does not make you anonymous, remove account identifiers, or guarantee that every application uses the tunnel. Review the provider’s privacy terms, use HTTPS where available, avoid entering sensitive credentials on unfamiliar pages, and keep iOS and the client updated.

Troubleshoot Common Shadowrocket Problems

The first troubleshooting step is to identify which stage failed: installation, subscription retrieval, profile parsing, VPN permission, connection establishment, routing, or application access. This prevents unrelated settings from being changed at the same time. Write down the exact error message and the network you were using. A profile that fails on mobile data but works on Wi-Fi points to a different cause from a profile that never appears after import.

The Subscription Does Not Import

Check the URL character by character, especially the beginning, ending, and any characters that may have been removed when copying. Confirm that the account is active and that the provider has not issued a replacement link. Try updating the subscription on a stable network, then close and reopen Shadowrocket. If the provider has an official subscription conversion option, use the format explicitly marked for Shadowrocket or compatible clients. Do not repeatedly submit a private URL to random online conversion tools.

Profiles Appear but Do Not Connect

First check whether iOS has granted Shadowrocket permission to add VPN configurations. Open the iPhone Settings app and review the VPN section if the client does not show an active connection. Then select another imported profile, because one server may be temporarily unavailable while others remain usable. Confirm that no other VPN or proxy application is active. If all profiles fail, refresh the subscription and contact the provider with the client name, iOS version, network type, profile label, and exact error message. Never send the full subscription URL in a public support channel.

The Client Says Connected but Apps Fail

Check the routing mode first. A direct rule may intentionally bypass the selected proxy, while a malformed custom rule may prevent a domain from resolving. Temporarily return to the provider’s original configuration and test again. If browsing works but one application does not, inspect that application’s region, account, DNS, and private relay settings. Also consider whether the app blocks proxy traffic or uses a separate connection method.

The Connection Drops After a Network Change

Switching from Wi-Fi to mobile data or moving between access points can interrupt an existing tunnel. Disable and re-enable the Shadowrocket connection, then test the selected profile again. If the problem repeats, try another profile or transport offered by the subscription. Keep the client and iOS updated, but avoid changing several advanced parameters at once because that makes it difficult to identify the cause.

Maintain the Setup Safely

A subscription is not a one-time installation artifact. Providers may add routes, remove unavailable profiles, rotate credentials, or adjust protocol parameters. Use Shadowrocket’s update function according to the provider’s instructions, and check that the update address still belongs to the intended provider. If an update suddenly introduces unfamiliar profile names or redirects you to an unexpected login page, stop and confirm the source before continuing.

Keep a simple record of the configuration that works: the subscription name, the preferred profile label, the routing mode, and the network where it was tested. Do not record the private URL in an unsecured public note. If you sell, lend, or reset the iPhone, remove the VPN configuration and delete the subscription entry. If you believe the URL has been exposed, request a replacement or revoke it through the provider’s account system rather than merely renaming the entry in Shadowrocket.

For regular use, review whether the selected plan matches your traffic pattern. QaVPN offers monthly plans of ¥9.9/month with 60GB, ¥18/month with 250GB, and ¥28/month with 500GB; traffic resets monthly on the activation date. It also offers traffic bundles of ¥158/300GB, ¥358/1000GB, and ¥658/3000GB that remain available until used and do not expire. The service permits unlimited simultaneous devices, so the same account can support an iPhone alongside other supported platforms, subject to the plan’s traffic rules.

If you need help, provide useful diagnostic information without revealing private credentials. Include the iPhone model only when relevant, iOS version, Shadowrocket version, whether you used Wi-Fi or mobile data, the profile label, the routing mode, and the exact error text. A support request that says only “it does not work” gives little information to distinguish a bad URL from a permission problem or an unavailable route.

Final checklist: Use a trustworthy app source, protect the subscription URL, import the correct format, test one profile in a simple mode, verify the public IP and real applications, and change only one troubleshooting variable at a time.

Shadowrocket setup becomes predictable when each layer is checked separately. The subscription supplies profiles, the profile defines protocol and server parameters, the routing mode decides which traffic uses them, and iOS controls the system VPN permission. Understanding those roles is more useful than repeatedly reinstalling the app. Once the basic connection is verified, you can evaluate alternative routes and rules based on your actual network and usage rather than relying on a single status message.

Start Free