Skip to content

Routing rules

Mole builds the Xray-core routing configuration on the client. This page describes what goes into it and in what order it applies.

Region presets

Mole uses the geosite and geoip lists built into Xray-core — there are no separate rule files to download.

Preset Rules
Russia geosite:category-ru, geoip:ru → direct
China geosite:cn, geoip:cn → direct
Iran geosite:category-ir, geoip:ir → direct

Presets are toggled independently on the Routing screen.

Custom rules

Your own domains are added on the same screen and support two actions:

  1. Direct: traffic bypasses the tunnel and goes out through the ISP.
  2. Block: the connection is dropped.

There is no separate "Proxy" action: anything that matches no rule goes through the proxy.

Order of evaluation

Rules are matched top to bottom; the first match wins:

  1. The server's own address → direct. This must come first, otherwise traffic to the server would re-enter the tunnel and the connection would deadlock.
  2. QUIC (UDP 443) → block, when Block QUIC is on (the default). Xray does not proxy QUIC under flow: xtls-rprx-vision, so blocking it makes apps fall back to HTTPS over TCP. Turn it off to let HTTP/3 through on servers that do carry UDP — Hysteria2, or VLESS without Vision.
  3. DNS (port 53, UDP and TCP) → the built-in resolver.
  4. Local network (geoip:private, geosite:private) → direct, when LAN bypass is on.
  5. Region presets → direct.
  6. Custom rules — Direct first, then Block.
  7. IPv6 (::/0) → block, when that option is on.
  8. Everything else → proxy.

Custom rules sit below the presets

User rules are evaluated after the region presets. If a preset is on and already covers a domain, your rule for that domain will not be reached.

domainStrategy is fixed at IPIfNonMatch: a domain is matched against the domain rules first and only resolved to an IP — for the IP rules — when nothing matched.

Full configurations

If a subscription serves a ready-made Xray config, none of the above applies: routing comes from the provider's config. See Full configurations.