2023-12-01 13:24:18 +08:00
---
2025-01-29 13:13:33 +08:00
icon : material/alert-decagram
2023-12-01 13:24:18 +08:00
---
2026-03-03 20:59:13 +08:00
!!! quote "Changes in sing-box 1.14.0"
:material-plus: [source_mac_address ](#source_mac_address )
2026-04-07 20:02:32 +08:00
:material-plus: [source_hostname ](#source_hostname )
:material-plus: [match_response ](#match_response )
:material-delete-clock: [rule_set_ip_cidr_accept_empty ](#rule_set_ip_cidr_accept_empty )
:material-plus: [response_rcode ](#response_rcode )
:material-plus: [response_answer ](#response_answer )
:material-plus: [response_ns ](#response_ns )
2026-04-10 11:54:47 +08:00
:material-plus: [response_extra ](#response_extra )
2026-04-10 15:02:55 +08:00
:material-plus: [package_name_regex ](#package_name_regex )
:material-alert: [ip_version ](#ip_version )
:material-alert: [query_type ](#query_type )
2026-03-03 20:59:13 +08:00
2025-08-14 11:04:04 +08:00
!!! quote "Changes in sing-box 1.13.0"
:material-plus: [interface_address ](#interface_address )
:material-plus: [network_interface_address ](#network_interface_address )
:material-plus: [default_interface_address ](#default_interface_address )
2025-01-29 13:13:33 +08:00
!!! quote "Changes in sing-box 1.12.0"
2025-03-06 14:02:16 +08:00
:material-plus: [ip_accept_any ](#ip_accept_any )
2025-01-29 13:13:33 +08:00
:material-delete-clock: [outbound ](#outbound )
2024-11-06 19:02:55 +08:00
!!! quote "Changes in sing-box 1.11.0"
:material-plus: [action ](#action )
:material-alert: [server ](#server )
:material-alert: [disable_cache ](#disable_cache )
:material-alert: [rewrite_ttl ](#rewrite_ttl )
2024-11-11 16:30:25 +08:00
:material-alert: [client_subnet ](#client_subnet )
:material-plus: [network_type ](#network_type )
:material-plus: [network_is_expensive ](#network_is_expensive )
:material-plus: [network_is_constrained ](#network_is_constrained )
2024-11-06 19:02:55 +08:00
2024-06-24 09:41:00 +08:00
!!! quote "Changes in sing-box 1.10.0"
:material-delete-clock: [rule_set_ipcidr_match_source ](#rule_set_ipcidr_match_source )
:material-plus: [rule_set_ip_cidr_match_source ](#rule_set_ip_cidr_match_source )
2024-09-15 11:42:57 +08:00
:material-plus: [rule_set_ip_cidr_accept_empty ](#rule_set_ip_cidr_accept_empty )
:material-plus: [process_path_regex ](#process_path_regex )
2024-06-24 09:41:00 +08:00
2024-02-03 17:45:27 +08:00
!!! quote "Changes in sing-box 1.9.0"
:material-plus: [geoip ](#geoip )
:material-plus: [ip_cidr ](#ip_cidr )
2024-02-09 18:37:25 +08:00
:material-plus: [ip_is_private ](#ip_is_private )
2024-11-06 19:02:55 +08:00
:material-plus: [client_subnet ](#client_subnet )
2024-02-21 14:27:55 +08:00
:material-plus: [rule_set_ipcidr_match_source ](#rule_set_ipcidr_match_source )
2024-02-03 17:45:27 +08:00
2023-12-01 13:24:18 +08:00
!!! quote "Changes in sing-box 1.8.0"
:material-plus: [rule_set ](#rule_set )
:material-plus: [source_ip_is_private ](#source_ip_is_private )
:material-delete-clock: [geoip ](#geoip )
:material-delete-clock: [geosite ](#geosite )
2022-07-08 17:01:38 +08:00
### Structure
```json
{
"dns" : {
"rules" : [
{
"inbound" : [
"mixed-in"
],
2022-08-16 23:46:05 +08:00
"ip_version" : 6 ,
2023-02-08 16:18:40 +08:00
"query_type" : [
"A" ,
"HTTPS" ,
32768
],
2022-07-08 17:01:38 +08:00
"network" : "tcp" ,
2022-07-27 12:03:07 +08:00
"auth_user" : [
2022-07-17 15:11:26 +08:00
"usera" ,
"userb"
],
2022-07-08 17:01:38 +08:00
"protocol" : [
"tls" ,
"http" ,
"quic"
],
"domain" : [
"test.com"
],
"domain_suffix" : [
".cn"
],
"domain_keyword" : [
"test"
],
"domain_regex" : [
"^stun\\..+"
],
"source_ip_cidr" : [
2022-08-25 22:22:20 +08:00
"10.0.0.0/24" ,
"192.168.0.1"
2022-07-08 17:01:38 +08:00
],
2023-12-01 13:24:18 +08:00
"source_ip_is_private" : false ,
2022-07-08 17:01:38 +08:00
"source_port" : [
12345
],
2022-07-27 12:03:07 +08:00
"source_port_range" : [
"1000:2000" ,
":3000" ,
"4000:"
],
2022-07-08 17:01:38 +08:00
"port" : [
80 ,
443
],
2022-07-27 12:03:07 +08:00
"port_range" : [
"1000:2000" ,
":3000" ,
"4000:"
],
"process_name" : [
"curl"
],
2022-08-31 14:33:52 +08:00
"process_path" : [
"/usr/bin/curl"
],
2024-09-15 11:42:57 +08:00
"process_path_regex" : [
"^/usr/bin/.+"
],
2022-07-27 12:03:07 +08:00
"package_name" : [
"com.termux"
],
2026-04-10 11:54:47 +08:00
"package_name_regex" : [
"^com\\.termux.*"
],
2022-07-27 12:03:07 +08:00
"user" : [
"sekai"
],
"user_id" : [
1000
],
2022-09-10 22:42:20 +08:00
"clash_mode" : "direct" ,
2024-11-11 16:30:25 +08:00
"network_type" : [
"wifi"
],
"network_is_expensive" : false ,
"network_is_constrained" : false ,
2025-08-14 11:04:04 +08:00
"interface_address" : {
"en0" : [
"2000::/3"
]
},
"network_interface_address" : {
"wifi" : [
"2000::/3"
]
},
"default_interface_address" : [
"2000::/3"
],
2026-03-03 20:59:13 +08:00
"source_mac_address" : [
"00:11:22:33:44:55"
],
"source_hostname" : [
"my-device"
],
2023-11-09 17:04:08 +08:00
"wifi_ssid" : [
"My WIFI"
],
"wifi_bssid" : [
"00:00:00:00:00:00"
],
2023-12-01 13:24:18 +08:00
"rule_set" : [
"geoip-cn" ,
"geosite-cn"
],
2024-06-24 09:41:00 +08:00
"rule_set_ip_cidr_match_source" : false ,
2026-04-07 20:02:32 +08:00
"match_response" : false ,
"ip_cidr" : [
"10.0.0.0/24" ,
"192.168.0.1"
],
"ip_is_private" : false ,
2026-04-10 10:15:02 +08:00
"ip_accept_any" : false ,
2026-04-07 20:02:32 +08:00
"response_rcode" : "" ,
"response_answer" : [],
"response_ns" : [],
"response_extra" : [],
2022-07-27 12:03:07 +08:00
"invert" : false ,
2022-07-08 17:01:38 +08:00
"outbound" : [
"direct"
],
2024-11-06 19:02:55 +08:00
"action" : "route" ,
2025-03-06 14:02:16 +08:00
"server" : "local" ,
// Deprecated
2026-04-07 20:02:32 +08:00
"rule_set_ip_cidr_accept_empty" : false ,
2025-03-06 14:02:16 +08:00
"rule_set_ipcidr_match_source" : false ,
"geosite" : [
"cn"
],
"source_geoip" : [
"private"
],
"geoip" : [
"cn"
]
2022-07-08 17:01:38 +08:00
},
{
"type" : "logical" ,
"mode" : "and" ,
"rules" : [],
2024-11-06 19:02:55 +08:00
"action" : "route" ,
"server" : "local"
2022-07-08 17:01:38 +08:00
}
]
}
}
```
!!! note ""
You can ignore the JSON Array [] tag when the content is only one item
### Default Fields
!!! note ""
The default rule uses the following matching logic:
2026-08-22 14:19:37 +08:00
(`domain` || `domain_suffix` || `domain_keyword` || `domain_regex` || `geosite` || `ip_cidr` || `ip_is_private` || `ip_accept_any` ) &&
2022-09-14 22:03:26 +08:00
(`port` || `port_range` ) &&
2026-08-22 14:19:37 +08:00
(`source_geoip` || `source_ip_cidr` || `source_ip_is_private` ) &&
2022-09-14 22:03:26 +08:00
(`source_port` || `source_port_range` ) &&
`other fields`
2022-07-08 17:01:38 +08:00
2026-03-25 10:32:09 +08:00
Additionally, each branch inside an included rule-set can be considered merged into the outer rule, while different branches keep OR semantics.
2023-12-01 13:24:18 +08:00
2022-07-08 17:01:38 +08:00
#### inbound
2023-12-14 22:23:52 +08:00
Tags of [Inbound ](/configuration/inbound/ ).
2022-07-08 17:01:38 +08:00
2022-08-16 23:46:05 +08:00
#### ip_version
2026-04-10 15:02:55 +08:00
!!! quote "Changes in sing-box 1.14.0"
This field now also applies when a DNS rule is matched from an internal
domain resolution that does not target a specific DNS server, such as a
[`resolve` ](../../route/rule_action/#resolve ) route rule action without a
`server` set. In earlier versions, only DNS queries received from a
client evaluated this field. See
[Migration ](/migration/#ip_version-and-query_type-behavior-changes-in-dns-rules )
for the full list.
Setting this field makes the DNS rule incompatible in the same DNS
configuration with Legacy Address Filter Fields in DNS rules, the Legacy
`strategy` DNS rule action option, and the Legacy
`rule_set_ip_cidr_accept_empty` DNS rule item. To combine with
address-based filtering, use the [`evaluate` ](../rule_action/#evaluate )
action and [`match_response` ](#match_response ).
2022-08-24 16:23:21 +08:00
4 (A DNS query) or 6 (AAAA DNS query).
2022-08-16 23:46:05 +08:00
Not limited if empty.
2023-02-08 16:18:40 +08:00
#### query_type
2026-04-10 15:02:55 +08:00
!!! quote "Changes in sing-box 1.14.0"
This field now also applies when a DNS rule is matched from an internal
domain resolution that does not target a specific DNS server, such as a
[`resolve` ](../../route/rule_action/#resolve ) route rule action without a
`server` set. In earlier versions, only DNS queries received from a
client evaluated this field. See
[Migration ](/migration/#ip_version-and-query_type-behavior-changes-in-dns-rules )
for the full list.
Setting this field makes the DNS rule incompatible in the same DNS
configuration with Legacy Address Filter Fields in DNS rules, the Legacy
`strategy` DNS rule action option, and the Legacy
`rule_set_ip_cidr_accept_empty` DNS rule item. To combine with
address-based filtering, use the [`evaluate` ](../rule_action/#evaluate )
action and [`match_response` ](#match_response ).
2023-02-08 16:18:40 +08:00
DNS query type. Values can be integers or type name strings.
2022-07-08 17:01:38 +08:00
#### network
`tcp` or `udp` .
2022-08-24 16:23:21 +08:00
#### auth_user
2022-07-17 15:11:26 +08:00
Username, see each inbound for details.
#### protocol
Sniffed protocol, see [Sniff ](/configuration/route/sniff/ ) for details.
2022-07-08 17:01:38 +08:00
#### domain
Match full domain.
#### domain_suffix
Match domain suffix.
#### domain_keyword
Match domain using keyword.
#### domain_regex
Match domain using regular expression.
#### geosite
2023-12-01 13:24:18 +08:00
!!! failure "Deprecated in sing-box 1.8.0"
2024-11-06 19:10:26 +08:00
Geosite is deprecated and will be removed in sing-box 1.12.0, check [Migration ](/migration/#migrate-geosite-to-rule-sets ).
2023-12-01 13:24:18 +08:00
2022-07-08 17:01:38 +08:00
Match geosite.
#### source_geoip
2023-12-01 13:24:18 +08:00
!!! failure "Deprecated in sing-box 1.8.0"
2024-11-06 19:10:26 +08:00
GeoIP is deprecated and will be removed in sing-box 1.12.0, check [Migration ](/migration/#migrate-geoip-to-rule-sets ).
2023-12-01 13:24:18 +08:00
2022-07-08 17:01:38 +08:00
Match source geoip.
#### source_ip_cidr
2023-12-01 13:24:18 +08:00
Match source IP CIDR.
#### source_ip_is_private
!!! question "Since sing-box 1.8.0"
Match non-public source IP.
2022-07-08 17:01:38 +08:00
#### source_port
Match source port.
2022-07-27 12:03:07 +08:00
#### source_port_range
Match source port range.
2022-07-08 17:01:38 +08:00
#### port
Match port.
2022-07-27 12:03:07 +08:00
#### port_range
Match port range.
#### process_name
2023-11-09 17:04:08 +08:00
!!! quote ""
2022-07-27 12:03:07 +08:00
Only supported on Linux, Windows, and macOS.
Match process name.
2022-08-31 14:33:52 +08:00
#### process_path
2023-11-09 17:04:08 +08:00
!!! quote ""
2022-08-31 14:33:52 +08:00
Only supported on Linux, Windows, and macOS.
Match process path.
2024-09-15 11:42:57 +08:00
#### process_path_regex
!!! question "Since sing-box 1.10.0"
!!! quote ""
Only supported on Linux, Windows, and macOS.
Match process path using regular expression.
2022-07-27 12:03:07 +08:00
#### package_name
Match android package name.
2026-04-10 11:54:47 +08:00
#### package_name_regex
!!! question "Since sing-box 1.14.0"
Match android package name using regular expression.
2022-07-27 12:03:07 +08:00
#### user
2023-11-09 17:04:08 +08:00
!!! quote ""
2022-07-27 12:03:07 +08:00
2022-08-09 16:36:17 +08:00
Only supported on Linux.
2022-07-27 12:03:07 +08:00
Match user name.
#### user_id
2023-11-09 17:04:08 +08:00
!!! quote ""
2022-07-27 12:03:07 +08:00
Only supported on Linux.
Match user id.
2022-09-10 22:42:20 +08:00
#### clash_mode
Match Clash mode.
2024-11-11 16:30:25 +08:00
#### network_type
!!! question "Since sing-box 1.11.0"
!!! quote ""
Only supported in graphical clients on Android and Apple platforms.
Match network type.
Available values: `wifi` , `cellular` , `ethernet` and `other` .
#### network_is_expensive
!!! question "Since sing-box 1.11.0"
!!! quote ""
Only supported in graphical clients on Android and Apple platforms.
Match if network is considered Metered (on Android) or considered expensive,
such as Cellular or a Personal Hotspot (on Apple platforms).
#### network_is_constrained
!!! question "Since sing-box 1.11.0"
!!! quote ""
Only supported in graphical clients on Apple platforms.
Match if network is in Low Data Mode.
2025-08-14 11:04:04 +08:00
#### interface_address
!!! question "Since sing-box 1.13.0"
!!! quote ""
Only supported on Linux, Windows, and macOS.
Match interface address.
#### network_interface_address
!!! question "Since sing-box 1.13.0"
!!! quote ""
Only supported in graphical clients on Android and Apple platforms.
Matches network interface (same values as `network_type` ) address.
#### default_interface_address
!!! question "Since sing-box 1.13.0"
!!! quote ""
Only supported on Linux, Windows, and macOS.
Match default interface address.
2026-03-03 20:59:13 +08:00
#### source_mac_address
!!! question "Since sing-box 1.14.0"
!!! quote ""
2026-03-06 21:43:21 +08:00
Only supported on Linux, macOS, or in graphical clients on Android and macOS. See [Neighbor Resolution ](/configuration/shared/neighbor/ ) for setup.
2026-03-03 20:59:13 +08:00
Match source device MAC address.
#### source_hostname
!!! question "Since sing-box 1.14.0"
!!! quote ""
2026-03-06 21:43:21 +08:00
Only supported on Linux, macOS, or in graphical clients on Android and macOS. See [Neighbor Resolution ](/configuration/shared/neighbor/ ) for setup.
2026-03-03 20:59:13 +08:00
Match source device hostname from DHCP leases.
2023-11-09 17:04:08 +08:00
#### wifi_ssid
!!! quote ""
2025-12-07 11:05:43 +08:00
Only supported in graphical clients on Android and Apple platforms, or on Linux.
2023-11-09 17:04:08 +08:00
Match WiFi SSID.
#### wifi_bssid
!!! quote ""
2025-12-07 11:05:43 +08:00
Only supported in graphical clients on Android and Apple platforms, or on Linux.
2023-11-09 17:04:08 +08:00
Match WiFi BSSID.
2023-12-01 13:24:18 +08:00
#### rule_set
!!! question "Since sing-box 1.8.0"
2024-06-26 00:45:10 +08:00
Match [rule-set ](/configuration/route/#rule_set ).
2023-12-01 13:24:18 +08:00
2024-02-21 14:27:55 +08:00
#### rule_set_ipcidr_match_source
!!! question "Since sing-box 1.9.0"
2024-06-24 09:41:00 +08:00
!!! failure "Deprecated in sing-box 1.10.0"
`rule_set_ipcidr_match_source` is renamed to `rule_set_ip_cidr_match_source` and will be remove in sing-box 1.11.0.
2024-06-26 00:45:10 +08:00
Make `ip_cidr` rule items in rule-sets match the source IP.
2024-06-24 09:41:00 +08:00
#### rule_set_ip_cidr_match_source
!!! question "Since sing-box 1.10.0"
2024-06-26 00:45:10 +08:00
Make `ip_cidr` rule items in rule-sets match the source IP.
2024-02-21 14:27:55 +08:00
2026-04-07 20:02:32 +08:00
#### match_response
!!! question "Since sing-box 1.14.0"
Enable response-based matching. When enabled, this rule matches against the evaluated response
(set by a preceding [`evaluate` ](/configuration/dns/rule_action/#evaluate ) action)
instead of only matching the original query.
The evaluated response can also be returned directly by a later [`respond` ](/configuration/dns/rule_action/#respond ) action.
Required for Response Match Fields (`response_rcode` , `response_answer` , `response_ns` , `response_extra` ).
2026-04-10 10:15:02 +08:00
Also required for `ip_cidr` , `ip_is_private` , and `ip_accept_any` when used with `evaluate` or Response Match Fields.
#### ip_accept_any
!!! question "Since sing-box 1.12.0"
Match when the DNS query response contains at least one address.
2026-04-07 20:02:32 +08:00
2022-07-27 12:03:07 +08:00
#### invert
Invert match result.
2022-07-08 17:01:38 +08:00
#### outbound
2025-01-29 13:13:33 +08:00
!!! failure "Deprecated in sing-box 1.12.0"
`outbound` rule items are deprecated and will be removed in sing-box 1.14.0, check [Migration ](/migration/#migrate-outbound-dns-rule-items-to-domain-resolver ).
2022-07-08 17:01:38 +08:00
Match outbound.
2023-03-29 10:30:31 +08:00
`any` can be used as a value to match any outbound.
2024-11-06 19:02:55 +08:00
#### action
2022-07-08 17:01:38 +08:00
2022-07-27 12:03:07 +08:00
==Required==
2024-11-06 19:02:55 +08:00
See [DNS Rule Actions ](../rule_action/ ) for details.
#### server
!!! failure "Deprecated in sing-box 1.11.0"
Moved to [DNS Rule Action ](../rule_action#route ).
2022-07-08 17:01:38 +08:00
2022-07-27 12:03:07 +08:00
#### disable_cache
2024-11-06 19:02:55 +08:00
!!! failure "Deprecated in sing-box 1.11.0"
2022-07-27 12:03:07 +08:00
2024-11-06 19:02:55 +08:00
Moved to [DNS Rule Action ](../rule_action#route ).
2023-03-25 12:03:23 +08:00
2024-11-06 19:02:55 +08:00
#### rewrite_ttl
2023-03-25 12:03:23 +08:00
2024-11-06 19:02:55 +08:00
!!! failure "Deprecated in sing-box 1.11.0"
2024-02-09 18:37:25 +08:00
2024-11-06 19:02:55 +08:00
Moved to [DNS Rule Action ](../rule_action#route ).
2024-02-09 18:37:25 +08:00
2024-11-06 19:02:55 +08:00
#### client_subnet
2024-05-12 15:06:21 +08:00
2024-11-06 19:02:55 +08:00
!!! failure "Deprecated in sing-box 1.11.0"
2024-02-09 18:37:25 +08:00
2024-11-06 19:02:55 +08:00
Moved to [DNS Rule Action ](../rule_action#route ).
2024-02-09 18:37:25 +08:00
2026-04-07 20:02:32 +08:00
### Legacy Address Filter Fields
!!! failure "Deprecated in sing-box 1.14.0"
Legacy Address Filter Fields are deprecated and will be removed in sing-box 1.16.0,
check [Migration ](/migration/#migrate-address-filter-fields-to-response-matching ).
2024-02-03 17:45:27 +08:00
2024-06-24 09:41:00 +08:00
Only takes effect for address requests (A/AAAA/HTTPS). When the query results do not match the address filtering rule items, the current rule will be skipped.
2024-02-03 17:45:27 +08:00
2024-02-14 20:42:58 +08:00
!!! info ""
2024-02-03 17:45:27 +08:00
2024-06-26 00:45:10 +08:00
`ip_cidr` items in included rule-sets also takes effect as an address filtering field.
2024-02-03 17:45:27 +08:00
2024-02-14 20:42:58 +08:00
!!! note ""
Enable `experimental.cache_file.store_rdrc` to cache results.
2024-02-03 17:45:27 +08:00
#### geoip
2025-03-06 14:02:16 +08:00
!!! failure "Removed in sing-box 1.12.0"
GeoIP is deprecated in sing-box 1.8.0 and removed in sing-box 1.12.0, check [Migration ](/migration/#migrate-geoip-to-rule-sets ).
2024-02-03 17:45:27 +08:00
Match GeoIP with query response.
#### ip_cidr
!!! question "Since sing-box 1.9.0"
Match IP CIDR with query response.
2026-04-07 20:02:32 +08:00
As a Legacy Address Filter Field, deprecated. Use with `match_response` instead,
check [Migration ](/migration/#migrate-address-filter-fields-to-response-matching ).
2024-02-03 17:45:27 +08:00
#### ip_is_private
!!! question "Since sing-box 1.9.0"
Match private IP with query response.
2026-04-07 20:02:32 +08:00
As a Legacy Address Filter Field, deprecated. Use with `match_response` instead,
check [Migration ](/migration/#migrate-address-filter-fields-to-response-matching ).
2024-06-24 09:41:00 +08:00
#### rule_set_ip_cidr_accept_empty
!!! question "Since sing-box 1.10.0"
2026-04-07 20:02:32 +08:00
!!! failure "Deprecated in sing-box 1.14.0"
`rule_set_ip_cidr_accept_empty` is deprecated and will be removed in sing-box 1.16.0,
check [Migration ](/migration/#migrate-address-filter-fields-to-response-matching ).
2024-06-26 00:45:10 +08:00
Make `ip_cidr` rules in rule-sets accept empty query response.
2024-06-24 09:41:00 +08:00
2026-04-07 20:02:32 +08:00
### Response Match Fields
!!! question "Since sing-box 1.14.0"
Match fields for the evaluated response. Require `match_response` to be set to `true`
and a preceding rule with [`evaluate` ](/configuration/dns/rule_action/#evaluate ) action to populate the response.
That evaluated response may also be returned directly by a later [`respond` ](/configuration/dns/rule_action/#respond ) action.
#### response_rcode
Match DNS response code.
Accepted values are the same as in the [predefined action rcode ](/configuration/dns/rule_action/#rcode ).
#### response_answer
Match DNS answer records.
Record format is the same as in [predefined action answer ](/configuration/dns/rule_action/#answer ).
#### response_ns
Match DNS name server records.
Record format is the same as in [predefined action ns ](/configuration/dns/rule_action/#ns ).
#### response_extra
Match DNS extra records.
Record format is the same as in [predefined action extra ](/configuration/dns/rule_action/#extra ).
2022-07-08 17:01:38 +08:00
### Logical Fields
#### type
`logical`
#### mode
`and` or `or`
#### rules
2026-03-25 10:32:09 +08:00
Included rules.