Proxa
Route, filter & watch traffic
$5.99
Run WireGuard, Tailscale and ZeroTier at once — and decide per rule which one each connection takes. Everything on device.
Proxa is a rule-based proxy and network toolbox for iPhone. Decide where every connection goes with a real rule engine, route it through the servers and networks you choose, block ads and trackers, and read your live traffic — all on device.
SEVERAL NETWORKS AT ONCE
• Connect WireGuard, Tailscale and ZeroTier at the same time. They are not modes you switch between: all three can be up together, each reachable by name.
• Rules decide which one carries each connection. Work domains over the tailnet, a lab subnet over ZeroTier, everything else direct — at the same moment, without touching a switch.
• Networks is a one-time in-app purchase. Set one up and see exactly what it would do before deciding.
ROUTE WITH RULES
• Domain, suffix, keyword, IP-CIDR, GEOIP and port rules, read top to bottom into policy groups.
• Send traffic through your own proxy servers or a subscription, or straight out DIRECT.
• Policy groups with health checks and automatic failover.
READ YOUR TRAFFIC
• A live request log: host, the rule that routed each connection and the node that carried it, with status, timing and size.
• HTTPS decryption for the hosts you list, with a guided certificate setup. Off until you turn it on; only the hosts you name are decrypted.
• WebSocket frames in both directions, plain http:// and ws:// included.
• Filter by status, method or blocked; search by host or URL.
CHOOSE YOUR RESOLVER
• Custom DNS: the system's, servers you name, DNS-over-HTTPS or DNS-over-TLS, with per-host overrides and a cache.
• Fake IP answers lookups on the device, so a domain rule matches even when the connection never shows a name — QUIC included.
• An unreachable resolver falls back to the system's, so a bad setting costs a moment rather than your connection.
THIRTEEN OUTBOUND PROTOCOLS
• HTTP, SOCKS5, Shadowsocks, VMess, VLESS + REALITY, Trojan, WireGuard, SSH, Snell, Hysteria2, TUIC, HTTP/3 and AnyTLS.
FROM THE HOME SCREEN
• A widget showing status, the node in use, traffic moved and connections allowed or refused.
• Control Center switches for capture and for the traffic log — reaching for "stop recording me" should not take your network down.
ON DEVICE BY DESIGN
• Everything runs on your device. Proxa has no account, no sign-in, and no servers that receive your traffic. What you capture stays in the app's private storage until you delete it. See our privacy policy.
Proxa uses a VPN configuration (Network Extension) to route this device's traffic through its on-device engine. It is not a commercial VPN service — there is no Proxa server, and traffic goes only to the proxies and networks you configure yourself.
Ratings & Reviews
- This app hasn’t received enough ratings or reviews to display an overview.
Added:
• WireGuard and SSH servers. Both were discarded at import before.
• Snell servers, versions 1 through 5 — pooled v2, HTTP and TLS obfuscation, per-user keys. Checked against Surge's own server. Dropped at import before.
• WireGuard tunnels can be typed in: Config ▸ Networks ▸ Add Tunnel takes the keys and endpoint your provider gave you. A .conf import fills the same form.
• Custom DNS: the system's resolver, servers you name, DNS-over-HTTPS or DNS-over-TLS, with [Host] overrides and a cache. An unreachable one falls back to the system's. "Override DNS" is off by default, which leaves Proxa's own lookups following your rules.
• Fake IP, under DNS ▸ Enhanced Mode. Proxa answers lookups with a stand-in address, so a connection arrives knowing its domain and domain rules match QUIC. Local names and captive portals still get real answers.
• HTTPS decryption, with a guided setup that installs Proxa's certificate through Safari. Only hosts you list are decrypted.
• Networks, with Proxa Premium. Route traffic through WireGuard, Tailscale or ZeroTier, chosen per rule. One purchase, not a subscription.
• A home-screen and lock-screen widget: status, node in use, traffic moved, connections allowed or refused. Its switch starts and stops Proxa without opening the app.
• Control Center switches (iOS 18) for Proxa and the traffic log.
• A node picker on the Dashboard, so choosing where traffic goes needs no policy group.
• Bulk cleanup in Config ▸ Servers: delete many nodes, or a whole subscription, at once.
• Plain HTTP and ws:// now show their requests and frames in Traffic.
• "Add Rule…" on a long press in Traffic, filled in with the domain and the node that served it.
Changed:
• Subscription import takes the routing rules too, not only the servers — from a Clash or Surge link, or a plain node list.
• Import reports what arrived, and what it could not use.
• "Start Capture" is now "Start Proxa", and the switch that records traffic is "Log traffic".
• Section headings no longer let rows scroll through them.
• Bigger touch targets on the controls hardest to hit: add, refresh, the ⋯ menus, and the Dashboard's Active Node rows.
• A traffic row leads with where the flow went: the node that carried it and the rule that chose it, where the method used to sit. That method was always CONNECT. It appears with the path only when the request was decrypted.
Fixed:
• Sites your rules send through a proxy could fail where the network answers DNS incorrectly — usually Google and X, while the rest worked. Proxa takes the name from the connection now, so a domain rule matches on iPhone.
• IPv6 did not work: requests to an IPv6 address stalled and no IP-CIDR6 rule matched. Proxa announced IPv6 on networks that have none, too.
• WebSocket connections went silent after connecting — nothing you sent reached the far end.
• Requests that only answer HEAD, and uploads using Expect: 100-continue, never finished.
• The Dashboard read 0 req/s while traffic was flowing.
• A [Host] override answered only the IPv4 lookup, so an iPhone could still reach the real host. It covers the whole name now.
• A custom DNS server with a port — 1.1.1.1:5335 — made Start fail silently.
• Proxa quitting unexpectedly could leave the iPhone with no internet until it restarted. Opening Proxa clears a stuck tunnel, and Settings can reset it.
• Choosing the IP-CIDR rule type crashed the app, since 1.0.
• A hosted Clash subscription imported zero servers, warning about a missing FINAL rule.
• A Surge subscription imported its servers but none of its routing.
• "Import Config" and the button beside it did not line up.
Known issues:
• Snell v6 needs a separate program the App Store cannot carry, and v1-v5 are TCP-only. Such nodes stay visible; a v6 node or a UDP flow is rejected.
• RULE-SET rules pointing at web-hosted lists are imported but not downloaded, so they never match. They are labelled "not fetched".
• The app is English-only.
The developer, Nexbit Pty LTd, indicated that the app’s privacy practices may include handling of data as described below. For more information, see the developer’s privacy policy .
Data Not Collected
The developer does not collect any data from this app.
Accessibility
The developer has not yet indicated which accessibility features this app supports. Learn More
Information
- Seller
- Nexbit Pty Ltd
- Size
- 174.9 MB
- Category
- Utilities
- Compatibility
Requires iOS 17.0 or later.
- iPhone
Requires iOS 17.0 or later. - iPad
Requires iPadOS 17.0 or later. - Apple Vision
Requires visionOS 1.0 or later.
- iPhone
- Languages
- English
- Age Rating
16+
- 16+
- Contains
Unrestricted Web Access
- Copyright
- © 2026 Nexbit Pty Ltd

