Chain/relay proxy sounds advanced: traffic through A then B. In practice latency and failure points double. I only chain when I need a specific egress or a single hop won't pass; for browsing, ChatGPT, or Steam, one solid hop is usually enough (pick a provider, latency test).
If System Proxy/Tun still can't reach the open internet, or the subscription is flaky, finish getting started before chaining.
When to chain, and when not to
| Situation | Verdict |
|---|---|
| Browsing, ChatGPT, Steam, normal sites | One solid hop is enough; chaining adds latency for nothing |
| You need a specific egress region the first hop cannot provide | Chain entry → exit |
| A single hop is blocked for one target only | Route that one domain through the chain; leave the rest alone |
| You just want "faster" | Do not chain—two hops are slower, not faster |
Setup: prove each hop, then join them
- Put the entry node alone in select; latency-test and open a target site.
- Do the same for the exit node.
- Join them with the client's relay/chain feature; send only one or two test domains through the chain first.
- When the connection page path looks right and the site works, widen the rules.
A relay group in Mihomo looks like this—two members in order, traffic traverses them sequentially:
proxy-groups:
- name: Chain-A-B
type: relay
proxies:
- HK-Entry
- JP-Exit
Two hops roughly add latency; bandwidth follows the weaker hop. "It feels slower" is often physics, not a misconfig. See slow speed.
Unstable? Split the chain
Don't change nodes, rules, and DNS at once. Test ① entry only → ② exit only → ③ chain again. Fix the failing segment. While triage, don't wrap the chain in fallback plus url-test—the failure surface explodes.
If both hops sit on the same congested region, try a different exit direction before adding hop three.
Loops, blank groups, one-site chains
Mutual refs or self-refs often show up as weird timeouts. Keep the chain one-way and clearly named; be careful with Merge/scripts (Merge, scripts). Wrong member names empty the group—see blank groups.
To chain only one AI site, point that domain at the chain group and leave other traffic on a normal group (Tun & AI). DNS/fake-ip issues can fake a "dead chain"—check fake-ip and DNS.
Tun, residential IP claims, safety
Tun doesn't make chains more reliable. Prove the chain on System Proxy first, then enable Tun (Tun). "Chain + residential IP" depends on whether your provider actually sells that egress—the client can't invent it.
Skip "one-click cracked chain configs." Use download center and safety notes.
Acceptance and rollback
Each hop works alone; the chained target works; connection paths match; you can drop back to a single hop; everyday sites aren't collateral damage. Write down working member names so the next edit doesn't typo the group empty.