Misc Options

ipv6 = false
loglevel = notify

skip-proxy =,,,,, localhost, *.local

tun-excluded-routes =,,
tun-included-routes =

Common Options

Enable full IPv6 support (Default: false)

ipv6 = false

loglevel (Default: notify)

loglevel = notify

One of verbose, info, notify or warning. It's not recommended to enable verbose in daily use because this will slow down the performance significantly.


skip-proxy =,,,,, localhost, *.local

In the iOS version, this option forces connection to these domain/IP ranges to be handled by Surge TUN, instead of Surge proxy. In the macOS version, these settings will be applied to the system when "Set as System Proxy" is enabled. This option is used to fix compatibility problems with some apps.

  • To specify a single domain, enter the domain name - for example, apple.com.
  • To specify all websites on a domain, use an asterisk before the domain name - for example, *apple.com.
  • To specify a specific part of a domain, specify each part - for example, store.apple.com.
  • To specify hosts or networks by IP addresses, enter a specific IP address such as or an address range, such as 192.168.2.* or

Notice: If you enter an IP address or address range, you will only be able to bypass the proxy when you connect to that host using that address, not when you connect to the host by a domain name that resolves to that address.


use-default-policy-if-wifi-not-primary = false


proxy-settings-interface = Wi-Fi

Real IP

always-real-ip = *.apple.com

This option will ask Surge to return a real IP address instead of a fake IP address when Surge VIF handles a DNS question.

Surge will forward the DNS packet to upstream DNS servers.

Hijack Other DNS Servers

hijack-dns =

By default, Surge only returns fake IP addresses for DNS queries sent to Surge DNS address ( Queries that are sent to standard DNS will be forwarded.

Some devices or software always use a hardcoded DNS server. (For example, Google Speakers always use You may use this option to hijack the query to get a fake address.

You may use hijack-dns = *:53 to hijack all DNS queries.

Excluded Routes

tun-excluded-routes =,,

Surge VIF can only process TCP and UDP protocols. Use this option to bypass specific IP ranges to allow all traffic to pass through.

Notice: This option only works for Surge VIF. Requests handled by Surge Proxy Server will not be affected. Combine 'skip-proxy' and 'tun-excluded-routes' to make sure that specific HTTP traffic bypasses Surge.

This option might cause a system error ENOMEM (Cannot allocate memory). It seems a bug in the iOS system. Please do not use this option if possible.

Included Routes

tun-included-routes =

By default, Surge VIF interface will declare itself as the default route. But since the Wi-Fi interface has a smaller route. Some traffic may not go through Surge VIF interface. Use this option to add a smaller route.

results matching ""

    No results matching ""