# Proxa — Route, filter & watch traffic

> Route, filter & watch traffic (iPhone/iPad app by Nexbit Pty LTd.)

- Source: https://appshunter.io/ios/app/proxa/id6792284572 (this page in markdown: same URL + `.md`)
- Developer: [Nexbit Pty LTd](https://appshunter.io/developer/6790751695)
- Category: Utilities, Developer Tools
- Price: $5.99
- Age rating: 17+
- Requires: iOS 17.0 · 167 MB
- Languages: American English
- Released: 2026-08-11
- Data updated: 2026-09-11
- User reviews in markdown: https://appshunter.io/ios/app/proxa/id6792284572/reviews.md

## What is Proxa?

Proxa is a rule-based proxy and network toolbox for iPhone. Decide where every connection goes with a real rule engine, route it through the servers and networks you choose, block ads and trackers, and read your live traffic — all on device.

SEVERAL NETWORKS AT ONCE
• Connect WireGuard, Tailscale and ZeroTier at the same time. They are not modes you switch between: all three can be up together, each reachable by name.
• Rules decide which one carries each connection. Work domains over the tailnet, a lab subnet over ZeroTier, everything else direct — at the same moment, without touching a switch.
• Networks is a one-time in-app purchase. Set one up and see exactly what it would do before deciding.

REACH WHAT IS ONLY REACHABLE FROM INSIDE
• A server can be reached through one of your networks, or through another server. A proxy that lives only inside your tailnet or your ZeroTier network becomes usable, without exposing it to the internet first.
• The connection to it is carried by whatever you chose. If that is off or unreachable, the server is not used — traffic is refused rather than quietly sent out directly.
• Part of the same one-time Networks purchase.

ROUTE WITH RULES
• Domain, suffix, keyword, IP-CIDR, GEOIP and port rules, read top to bottom into policy groups.
• Send traffic through your own proxy servers or a subscription, or straight out DIRECT.
• Policy groups with health checks and automatic failover.

READ YOUR TRAFFIC
• A live request log: host, path, method, status, timing and size.
• HTTPS decryption for the hosts you list, with a guided certificate setup. Off until you turn it on; only the hosts you name are decrypted.
• WebSocket frames in both directions, plain http:// and ws:// included.
• Filter by status, method or blocked; search by host or URL.

CHOOSE YOUR RESOLVER
• Custom DNS: the system's, servers you name, DNS-over-HTTPS or DNS-over-TLS, with per-host overrides and a cache.
• An unreachable resolver falls back to the system's, so a bad setting costs a moment rather than your connection.

THIRTEEN OUTBOUND PROTOCOLS
• HTTP, SOCKS5, Shadowsocks, VMess, VLESS + REALITY, Trojan, WireGuard, SSH, Snell, Hysteria2, TUIC, HTTP/3 and AnyTLS.

FROM THE HOME SCREEN
• A widget showing status, the node in use, traffic moved and connections allowed or refused.
• Control Center switches for capture and for the traffic log — reaching for "stop recording me" should not take your network down.

ON DEVICE BY DESIGN
• Everything runs on your device. Proxa has no account, no sign-in, and no servers that receive your traffic. What you capture stays in the app's private storage until you delete it. See our privacy policy.

Proxa uses a VPN configuration (Network Extension) to route this device's traffic through its on-device engine. It is not a commercial VPN service — there is no Proxa server, and traffic goes only to the proxies and networks you configure yourself.


## Version history (last 3 releases)

### 1.2 — 2026-09-03

Added:
• Chained servers, with Proxa Premium. A server can now be reached *through* one of your networks or through another server: open the server, and under Connect Via choose what carries it. A proxy that only exists inside your tailnet or your ZeroTier network becomes usable, and the connection to it never crosses the open internet. If whatever carries it is off or unreachable, that server is not used — traffic is refused rather than quietly sent out directly. The screen says so before you save, and a server that cannot be carried at all is not offered the choice.

Fixed:
• AirDrop stopped working while Proxa was running.
• A connection refused by a network now says the network could not reach the address, instead of blaming the server it never got to. A server that refused for its own reasons says which reason.
• A network that has not finished connecting no longer holds a request for twenty seconds before giving up on it.

Known issues:
• Snell v6 needs a separate program the App Store cannot carry, and v1-v5 are TCP-only. Such nodes stay visible; a v6 node or a UDP flow is rejected.
• RULE-SET rules pointing at web-hosted lists are imported but not downloaded, so they never match. They are labelled "not fetched".
• The app is English-only.

### 1.1 — 2026-08-26

Added:
• WireGuard and SSH servers. Both were discarded at import before.
• Snell servers, versions 1 through 5 — pooled v2, HTTP and TLS obfuscation, per-user keys. Checked against Surge's own server. Dropped at import before.
• WireGuard tunnels can be typed in: Config ▸ Networks ▸ Add Tunnel takes the keys and endpoint your provider gave you. A .conf import fills the same form.
• Custom DNS: the system's resolver, servers you name, DNS-over-HTTPS or DNS-over-TLS, with [Host] overrides and a cache. An unreachable one falls back to the system's. "Override DNS" is off by default, which leaves Proxa's own lookups following your rules.
• Fake IP, under DNS ▸ Enhanced Mode. Proxa answers lookups with a stand-in address, so a connection arrives knowing its domain and domain rules match QUIC. Local names and captive portals still get real answers.
• HTTPS decryption, with a guided setup that installs Proxa's certificate through Safari. Only hosts you list are decrypted.
• Networks, with Proxa Premium. Route traffic through WireGuard, Tailscale or ZeroTier, chosen per rule. One purchase, not a subscription.
• A home-screen and lock-screen widget: status, node in use, traffic moved, connections allowed or refused. Its switch starts and stops Proxa without opening the app.
• Control Center switches (iOS 18) for Proxa and the traffic log.
• A node picker on the Dashboard, so choosing where traffic goes needs no policy group.
• Bulk cleanup in Config ▸ Servers: delete many nodes, or a whole subscription, at once.
• Plain HTTP and ws:// now show their requests and frames in Traffic.
• "Add Rule…" on a long press in Traffic, filled in with the domain and the node that served it.

Changed:
• Subscription import takes the routing rules too, not only the servers — from a Clash or Surge link, or a plain node list.
• Import reports what arrived, and what it could not use.
• "Start Capture" is now "Start Proxa", and the switch that records traffic is "Log traffic".
• Section headings no longer let rows scroll through them.
• Bigger touch targets on the controls hardest to hit: add, refresh, the ⋯ menus, and the Dashboard's Active Node rows.
• A traffic row leads with where the flow went: the node that carried it and the rule that chose it, where the method used to sit. That method was always CONNECT. It appears with the path only when the request was decrypted.

Fixed:
• Sites your rules send through a proxy could fail where the network answers DNS incorrectly — usually Google and X, while the rest worked. Proxa takes the name from the connection now, so a domain rule matches on iPhone.
• IPv6 did not work: requests to an IPv6 address stalled and no IP-CIDR6 rule matched. Proxa announced IPv6 on networks that have none, too.
• WebSocket connections went silent after connecting — nothing you sent reached the far end.
• Requests that only answer HEAD, and uploads using Expect: 100-continue, never finished.
• The Dashboard read 0 req/s while traffic was flowing.
• A [Host] override answered only the IPv4 lookup, so an iPhone could still reach the real host. It covers the whole name now.
• A custom DNS server with a port — 1.1.1.1:5335 — made Start fail silently.
• Proxa quitting unexpectedly could leave the iPhone with no internet until it restarted. Opening Proxa clears a stuck tunnel, and Settings can reset it.
• Choosing the IP-CIDR rule type crashed the app, since 1.0.
• A hosted Clash subscription imported zero servers, warning about a missing FINAL rule.
• A Surge subscription imported its servers but none of its routing.
• "Import Config" and the button beside it did not line up.

Known issues:
• Snell v6 needs a separate program the App Store cannot carry, and v1-v5 are TCP-only. Such nodes stay visible; a v6 node or a UDP flow is rejected.
• RULE-SET rules pointing at web-hosted lists are imported but not downloaded, so they never match. They are labelled "not fetched".
• The app is English-only.

### 1.0 — 2026-08-11

No release notes.

## More apps by Nexbit Pty LTd

- [NomadLink: Travel eSIM](https://appshunter.io/ios/app/nomadlink-travel-esim/id6790751693)

All apps by Nexbit Pty LTd: https://appshunter.io/developer/6790751695

## Related topics

[zerotier](https://appshunter.io/ios/topics/zerotier)

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-09-11.*
