Misc Options

ipv6 = false
loglevel = notify

skip-proxy =,,,,, localhost, *.local

tun-excluded-routes =,,
tun-included-routes =

Common Options

Enable full IPv6 support (Default: false)

ipv6 = false

loglevel (Default: notify)

loglevel = notify

One of verbose, info, notify or warning. It's not recommended to enable verbose in daily use because this will slow down the performance significantly.


skip-proxy =,,,,, localhost, *.local

In iOS version, this option forces connections to these domain/IP ranges to be handled by Surge TUN, instead of Surge proxy. In macOS version, these settings will be applied to system when "Set as System Proxy" is enabled. This option is used to fix compatibility problems with some apps.

  • To specify a single domain, enter the domain name - for example, apple.com.
  • To specify all websites on a domain, use an asterisk before the domain name - for example, *apple.com.
  • To specify a specific part of a domain, specify each part - for example, store.apple.com.
  • To specify hosts or networks by IP addresses, enter a specific IP address such as or an address range, such as 192.168.2.* or

Notice: If you enter an IP address or address range, you will only be able to bypass the proxy when you connect to that host using that address, not when you connect to the host by a domain name that resolves to that address.


use-default-policy-if-wifi-not-primary = false


proxy-settings-interface = Wi-Fi

Real IP

always-real-ip = *.apple.com

This option will ask Surge to return a real IP address instead of a fake IP address when a DNS question is handled by Surge VIF.

Surge will forward the DNS packet to upstream DNS servers.

Hijack Other DNS Servers

hijack-dns =

By default, Surge only returns fake IP addresses for DNS queries sent to Surge DNS address ( Queries which are sent to standard DNS will be simply forwarded.

Some devices or softwares always use a hardcode DNS server. (For example, Google Speakers always use You may use this option to hijack the query to get a fake address.

You may use hijack-dns = *:53 to hijack all DNS queries.

Excluded Routes

tun-excluded-routes =,,

Surge VIF can only process TCP and UDP protocols. Use this option to bypass specific IP ranges to allow all traffic to pass through.

Notice: This option only works for Surge VIF. Requests handled by Surge Proxy Server will not be affected. Combine 'skip-proxy' and 'tun-excluded-routes' to make sure that certain HTTP traffic bypasses Surge.

This option might cause a system error ENOMEM (Cannot allocate memory). It seems a bug in iOS system. Please do not use this option if possible.

Included Routes

tun-included-routes =

By default, Surge VIF interface will declare itself as the default route. But since the Wi-Fi interface has a smaller route. Some traffic may not go through Surge VIF interface. Use this option to add a smaller route.

results matching ""

    No results matching ""