fake-ip means Clash may answer "what is this domain’s IP?" with an internal fake address so rules can steer quickly. Faster matching; some apps that insist on "real" resolution misbehave.
Defaults often enable it for speed. When LAN breaks or an app complains about certs/odd IPs, compare redir-host—do not reinstall first. Overview: DNS.
fake-ip vs redir-host
If proxying is fine and LAN works, keep fake-ip. If corp LAN/NAS only fails under Clash, add fake-ip filters for those suffixes; still broken → trial redir-host. "Rules do nothing" is sometimes a DNS-mode mismatch (routing).
| Mode | How it answers DNS | Good for | Watch out |
|---|---|---|---|
| fake-ip | Returns an internal fake address | Fast rule matching, many domains | Apps that re-resolve or pin real IPs |
| redir-host | Returns the real resolved IP | LAN, NAS, stubborn apps | Slightly slower first match |
Filter private names
Exclude .local, router UI hosts, and corp suffixes from fake-ip. Write filters for your network—do not paste giant unrelated lists. Restart connections after changes; old sockets may cache answers. A minimal exclusion looks like this:
fake-ip-filter:
- '*.lan'
- '*.local'
- '192.168.*.*'
- '10.*.*.*'
- '172.16.*.*'
Add your router and NAS suffixes there before flipping the whole mode off.
Streaming, IM, and stacked DNS
For YouTube/Netflix or IM voice issues, confirm proxy/nodes before blaming DNS (streaming, IM). System DNS + browser DoH + Clash DNS fighting each other: leave one path while testing. Router DNS filters or ad-blocking DNS: disable one side for A/B. Record baselines when nslookup and the browser disagree.
When not to touch it
If nothing is wrong, do not "optimize" fake-ip. Skipping cert validation is a different risk knob—especially on public Wi‑Fi. Keep a note of the working mode and filter list. Chasing zero-millisecond gains usually trades stability for nothing.
Acceptance
Proxied sites work; LAN/admin pages still open; the broken app recovers; connections look expected. Stay on verifiable builds (download center). If a specific site still misbehaves after a mode switch, the cause is more likely nodes or routing than DNS—see routing basics.
Decision shortcut
| Observed problem | Try first |
|---|---|
| NAS / router UI unreachable under Clash | Add suffix to fake-ip-filter |
| One app rejects the connection cert/IP | Exclude its domain, then redir-host |
| Everything works | Leave fake-ip alone |