A VPN icon in the Shadowrocket status bar only means the local tunnel is up. It does not guarantee the site will open, and it does not guarantee the server you selected still works. When Safari will not load a page, many people delete the app and install it again. That usually wastes time. The problem is rarely a broken app file. It is usually the network, the server, or the subscription.

Check three prerequisites first. A server is selected in the SERVER list. Global Routing is set—Config for everyday use. Settings already shows a Shadowrocket VPN. If any of these is missing, the toggle can be on and still do nothing. If SERVER still shows only Add Server, go back to adding a configuration and check that you did not paste a subscription URL into Host. If the VPN is missing from system settings, go back to permission: delete the leftover profile, open the app, and tap Allow.

If all three are in place and sites still fail, set Global Routing to Direct and open the same site again. If Direct also fails, turn the toggle off and check Wi-Fi or cellular: wrong hotspot, cellular data off, or a captive portal that needs a login. If Direct works, the phone can reach that site on its own. The problem is on the proxy path: select another server, or ask your provider to refresh the subscription.

If sites that already work without the proxy still open, but sites that need the proxy do not, that is usually the server, not a broken app. Config is supposed to split traffic by rules. When that is the only symptom, change servers first—do not jump to Restore Default Config. Restore the default file only if you already edited rules, Proxy works, and Config does not.

Connectivity Test measures the path to the server. On a timeout or a very high number, change servers. Do not hammer the same one. If the test looks fine but pages still fail, still run the Direct comparison—the test is not the load time of a specific site. Logs are in Settings → Diagnostics. Turn on Enable Logging, then read VPN Logs. They only describe the local tunnel. They cannot tell you whether a server has expired. Turn logging off when you are done.

Heat and fast battery drain often come from leaving Proxy on for a long time or running tests over and over. Switch back to Config and stop the tests. If On Demand is on, the tunnel can come back up after you think you turned it off. Leave it Off until you understand it.

Before you switch phones, know what you are moving. Export Servers on the Data tab copies only the SERVER list. iCloud backups for configurations and config files must be turned on yourself. Rule files live on the Config tab and are handled separately. Delete Local Servers clears the list on this device—export first. On a new phone: install the official app, finish VPN permission, then import or subscribe again. An expired subscription stays expired after you move it.

Do not start with these: downloading an IPA, switching to a shared account, reinstalling three times, adding random remote rules in Config, or setting Plugin to kcptun just to try it. Those steps add new variables and make the original problem impossible to describe. A useful comparison changes one condition at a time.

Write the symptom as one sentence you could hand to someone else. Troubleshooting gets faster. For example: "The toggle is on. Direct opens the same site. Config does not. The test times out." That already points to the server. Or: "Direct fails too." That points to the phone network. Or: "SERVER is empty. Type was Shadowsocks, but the value was a full https URL." That points to the wrong field. A provider can work from sentences like these. They cannot work from "it just doesn't work, I already reinstalled."

If the same server worked yesterday and fails today, suspect the subscription or the provider first—not a store package that suddenly went bad. A new Wi-Fi network, a work network that blocks tunnels, or iOS deleting the VPN profile can all look like "it used to be fine." Confirm the VPN entry is still in Settings, then check that an update did not empty the list, and only then consider a reinstall. After a reinstall you must redo permission and import. That costs more than a comparison.

If Safari fails but one app works—or the reverse—that is usually rules or that app's own networking, not "half of the client is broken." Use Safari as the baseline, then test that app alone. Do not run several network tools that fight for the same system VPN slot. The last profile written can replace Shadowrocket. The toggle may still look on while another VPN is in control.

If the toggle does nothing, do not treat it as a server problem yet. Check Settings for the VPN entry, and whether the name changed. After another tool overwrites it, the Shadowrocket toggle often does nothing. Deleting the conflicting profile and opening the app to grant permission again is more on target than changing servers. Once the slot is Shadowrocket again, run the Direct comparison. If permission keeps failing, confirm the install is the official App Store copy—not a profile, enterprise-signed build, or a copy from a shared account. With a shady install, the comparison table stops working. Go back to the official app, then run Direct from scratch.

When you compare, write down the site, the mode, and the server before you change anything. Use a site you already know, switch from Config to Direct, and leave the server alone. Change the server only after you have a conclusion. Shared home Wi-Fi, a hotel captive portal, or a work proxy can make Direct fail too. That is not a Shadowrocket issue. Get the system network to the point where that site opens, then turn the toggle on. Otherwise you will mistake a portal block for an expired server.

The tutorial has a comparison table for a dead toggle, bad tests, a VPN you cannot add, and an empty list. Get Started writes the first run as one sequence. This article only asks you to pause when a page will not load, finish the Direct comparison, then pick the next step. Most of the time that step is a different server or a network check—not buying the client again. If you do not have the official app yet, verify it on the download page before you troubleshoot, or you add an unknown package as another variable.