# Surge 5 — Advanced Network Toolbox

> Advanced network utility for developers to intercept, process, and forward network traffic. (iPhone/iPad app by Surge Networks Inc..)

- Source: https://appshunter.io/ios/app/surge-5/id1442620678 (this page in markdown: same URL + `.md`)
- Developer: [Surge Networks Inc.](https://appshunter.io/developer/1442620677)
- Category: Developer Tools, Utilities
- Price: Free with in-app purchases
- Rating: 4.10/5 from 984 App Store ratings · 442 written reviews indexed
- Age rating: 4+
- Requires: iOS 17.0 · 68 MB
- Languages: American English, Chinese (Simplified, China), Chinese (Traditional, Hong Kong SAR China)
- Released: 2018-11-17
- Data updated: 2026-08-26
- Monetization: free with in-app purchases
- User reviews in markdown: https://appshunter.io/ios/app/surge-5/id1442620678/reviews.md

## What is Surge 5?

Surge is an advanced network toolbox and proxy utility. It is designed for developers and therefore requires professional knowledge to use.

These four capabilities form the core workflow of Surge:

· Takeover: Take over the network connections sent by the device. Surge supports both proxy service and virtual NIC takeover, capturing HTTP, HTTPS, TCP, and UDP traffic from any app — even those ignoring proxy settings. All features work on the cellular network.
· Processing: Modify the requests and responses that have been taken over: URL rewrite, header and body rewrite, local file mapping, custom DNS answers, and JavaScript-based modification.
· Forwarding: Forward requests to proxy servers, either globally or driven by a flexible rule system. Policy groups select the best server automatically by latency, availability, or learned connection quality.
· Intercept: Record and inspect requests and responses, including headers and bodies, and decrypt HTTPS traffic with MITM.

Highlighted Features

· Proxy protocols: HTTP/HTTPS, SOCKS5, SOCKS5-TLS, HTTP2 CONNECT, TrustTunnel, Shadowsocks, Snell, Trojan, Hysteria 2, AnyTLS, and SSH, with UDP relay support.
· Used as a WireGuard or Tailscale client, converting the L3 VPN into a proxy policy.
· Rules based on domain match/suffix/keyword/wildcard, CIDR IP range, GeoIP, ASN, protocol, port, and logical combinations; reusable rule sets hosted locally or remotely.
· Policy groups: manual selection, automatic latency testing, fallback, load balancing, and the self-learning Smart group.
· Complete DNS suite: DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, DNS-over-TLS, and concurrent queries for the fastest answer.
· Local DNS mapping (equivalent to /etc/hosts) with wildcards, aliases, and per-domain DNS servers. Switch your app between production and development environments without changing any code.
· Decrypt HTTPS traffic with Man-in-the-Middle and a built-in CA certificate generator.
· Record and display HTTP requests and responses with JSON, text, image, and video viewers for the captured body; album mode for the request list; pre-filter for capturing.
· Raw L3 packet capture.
· Scripting: extend Surge with JavaScript — modify requests and responses, write custom rules, customize DNS answers, and run scheduled tasks.
· Block unwanted requests by rules with high-performance pre-matching.
· Measure traffic usage and network speed on Wi-Fi, cellular, and proxy connections.
· Remote Dashboard: observe and debug traffic in real time from a Mac via Wi-Fi or USB, including cellular traffic.
· Surge Ponte: access your home or office network remotely via your own devices, with no third-party service involved.
· HTTPS proxy protocol supports client-side TLS certificate validation.
· Safari extension to add rules; widgets and Information Panel for quick control.
· Sync profiles across devices with iCloud Drive or Dropbox.
· Full IPv6 support, TLS 1.3, HTTP/2, and QUIC.
· High performance and industrial-grade stability, suitable for intensive use.

Surge does not provide any proxy or VPN service; you need to configure your own servers.

You may read the online manual for more information: https://nssurge.com/support

Terms and Conditions: https://nssurge.com/legal/terms
Privacy Policy: https://nssurge.com/legal/privacy

## Key features

- Network connection takeover
- Modify network requests/responses
- Forward traffic to other proxies
- Intercept and save network data
- Decrypt HTTPS traffic
- Rule-based forwarding
- Ad blocking by domain

## Pricing and in-app purchases

Base price: Free.

**Subscriptions**

| Subscription | Price | Period |
| --- | --- | --- |
| Feature Subscription | $14.99 | per year |

**One-time purchases**

| Purchase | Price | Type |
| --- | --- | --- |
| Surge Pro | $49.99 | one-time |


## Chart rankings

- #22 in Top Free · Developer Tools (US App Store)
- #8 in Top Grossing · Developer Tools (US App Store)

## Recent user reviews (10 of 442)

All indexed reviews: https://appshunter.io/ios/app/surge-5/id1442620678/reviews.md

### 1/5 — 这个每年要交15美元,千万不要购买，感觉不如小火箭，还这么贵

*2026-07-30, version 5.20.0*

这个每年要交15美元,千万不要购买，感觉不如小火箭，还这么贵

### 5/5 — restore purchase

*2026-07-30*

Hi there! I purchased the Sure app from the Chinese mainland App Store back in 2016, and I still have my valid order number for it. Unfortunately, the app was removed from the China store later on. I’ve now downloaded it again using my US Apple ID, so could you tell me how to restore my previous purchase?

### 4/5 — mac和ios组合订阅收费

*2026-07-19, version 5.19.0*

建议增加mac和ios组合订阅收费，每次续费还得两边都看，都维护

### 1/5 — 50u喂狗

*2026-07-09, version 5.19.0*

作者封授权，小心点，到时候用都用不了

### 5/5 — AK

*2026-07-05, version 5.19.0*

AK

### 1/5 — DON’T INSTALL!! PPL USE IT TO SCAM OR HACK

*2026-06-28, version 5.19.0*

UNINSTALL & REPORT

### 1/5 — 50$当喂狗了

*2026-06-28, version 5.19.0*

吃相好难看 一个协议就要续费

### 3/5 — 圈X和surge用同样的节点，都是默认设置规则模式下用Surge，X软件没有消息推送，麻烦更新一下软件

*2026-06-18, version 5.19.0*

圈X和surge用同样的节点，都是默认设置规则模式下用Surge，X软件没有消息推送，用圈X的却可以，麻烦更新一下软件

### 5/5 — 用过的最好工具

*2026-06-17, version 5.19.0*

所用工具里面的No.1没有之一

### 1/5 — 不要买了,支持的协议太少了

*2026-06-16, version 5.19.0*

不要当大冤种

## Frequently asked questions about Surge 5

### What does Surge 5 do?

Surge 5 is an advanced network utility designed for developers. It allows you to take over device network connections, process and modify network requests and responses, forward traffic to other proxy servers, and intercept specific data. It's a powerful tool for network analysis and debugging.

### What are the key features of Surge 5?

Key features include taking over HTTP/HTTPS/TCP traffic, modifying requests/responses with JavaScript, forwarding traffic with flexible rules, intercepting and decrypting HTTPS traffic, ad blocking, local DNS mapping, and detailed traffic measurement. It also supports various proxy protocols and advanced DNS features.

### Is Surge 5 free to use?

The application is available for free with in-app purchases. While the core functionality is accessible, certain advanced features or expanded capabilities may require purchasing through in-app transactions.

### Who is the target audience for Surge 5?

Surge 5 is specifically designed for developers and individuals with professional knowledge of networking and web development. Its advanced features require a technical understanding to utilize effectively for tasks like debugging and network analysis.

### What are common use cases for Surge 5?

Common use cases include debugging network issues in applications, analyzing API requests and responses, testing network configurations, blocking ads on a device level, and switching between development and production environments without code changes using local DNS mapping.

## Version history (last 5 releases)

### 5.21.1 — 2026-08-11

What's New

Surge as MTProto Server
- Surge now can operate as an incoming MTProto proxy server for Telegram.  Please read manual for more information: https://manual.nssurge.com/

Tailscale
- Added interactive Tailscale sign-in on iOS and macOS. Resolve the issue where some enterprise users are unable to obtain the auth key.
- Added automatic Tailscale routing. Surge can discover the tailnet’s MagicDNS suffix and peer IPv4/IPv6 addresses, then automatically route matching domains and peer IP traffic through the corresponding Tailscale policy.
- Automatic Tailscale routing is enabled by default and can be disabled with `auto-add-magic-dns-rule = false`.
- Improved Tailscale session warm-up and recovery. Sessions now retry MagicDNS discovery after startup failures and network changes without requiring matching traffic to arrive first.
- Tailscale sessions now stay active by default. An omitted `idle-keepalive`, `0`, or `-1` keeps the session always active; set a positive value to enable idle teardown.
- Tailscale can now begin handling traffic as soon as a valid network map is received, without waiting for the home DERP connection to be established.
- Improved recovery after network changes and control-server reconnections by preserving the last known home DERP region and retrying peer handshakes at the appropriate time.
- Aligned DERP measurement and selection behavior with official Tailscale client, improving compatibility with custom DERP maps, STUN-only nodes, fallback probes, and temporarily unavailable control connections.
- Sensitive values such as authentication keys and authorization URLs are now redacted from verbose Tailscale control logs.

TLS
- Added `server-cert-verify-name` to independently specify the hostname used for proxy server certificate verification without changing SNI. This parameter applies to all TLS- and QUIC-based proxy protocols.

ECN
- Reworked ECN configuration and packet handling across QUIC, WireGuard, Tailscale, Ponte, and nested UDP tunnels.
- Correctly preserves ECN and DSCP/TOS metadata across IPv4 and IPv6 encapsulation and decapsulation.
- For QUIC-based proxy protocols, when ECN is enabled, anomalies will be automatically detected and fallback to non-ECN handling.
- ECN is now enabled by default for QUIC-based proxy protocols on supported systems. WireGuard and Tailscale remain disabled by default. Use `ecn=false` or `ecn=true` to override the default explicitly.
- Surge Ponte now also has ECN enabled by default, and the `client-use-ecn` parameter has been removed.

DNS
- Optimized TCP connection establishment for `prefer-v4` and `prefer-v6`. In earlier versions, these two parameters indicated which record to use when a domain name had both A and AAAA records. Now, during the TCP handshake, A or AAAA records are used preferentially; if the handshake cannot be completed within 3 seconds, other records will start to be tried.
- Added DNS-over-TCP support. DNS server settings now accept `tcp://hostname[:port]`.

iOS
- Raised the minimum system requirement to iOS 17.
- Reworked Shortcuts and App Intent support and improved the reliability of App Intent operations.
- Added manual Suspend and Bypass Suspension controls. The Ponte management page, scripts, and local proxy services remain available while Surge is suspended.
- Snell Server can now be configured and used on iOS and tvOS.

Codebase Refactoring

After more than a decade of development, the Surge codebase has grown into a large and complex project. To further improve reliability, we have introduced AI-assisted code review across the entire codebase.

Every code change is independently reviewed by Fable 5, GPT-5.6 Sol, and a human developer before being merged, helping us identify potential security issues, rare crash scenarios, and subtle correctness problems.

Due to the large number of updates, please refer to the Mac version release notes for details: https://nssurge.com/support/mac/release-notes

### 5.20.0 — 2026-07-20

### Tailscale Support

Surge now supports Tailscale as a policy.

With this feature, Surge can join your Tailscale tailnet directly and route selected traffic through Tailscale peers using the existing Surge rule system. You can use Tailscale IPs, and tailnet-only services together with Surge policies, policy groups, DNS handling, traffic logging, and rule-based routing.

Please check the manual for more information: https://manual.nssurge.com/policy/tailscale.html

### Snell v6

Introduced Snell v6, featuring PSK-derived deployment-level protocol diversity that generates unique traffic characteristics for each deployment, reducing reliance on a single protocol fingerprint while preserving Snell’s core goals of performance, deployment simplicity, accurate error reporting, and full TCP semantics. Snell v6 also adds new IPv4/IPv6 network stack controls including dns-ip-preference and multi-address listen support, and is currently available for beta testing.

Please check our blog for more information: https://nssurge.com/blog/snell-v6/

### Codebase Refactoring

We have completed a comprehensive review of Surge’s core functionality and resolved numerous implementation issues, edge cases, and long-standing inconsistencies.

This ongoing refactoring effort improves maintainability and helps provide a more robust foundation for future development.

### WireGuard

WireGuard policies now use a dedicated native RTT test when no DNS server is configured, making them suitable for peer-to-peer access without requiring a reachable test URL. When a DNS server is configured, the policy is treated as a standard outbound proxy and continues to use the regular URL test process. WireGuard runtime information and diagnostics have also been updated to reflect the applicable testing mode.

### Minor Improvements
- The Smart Group algorithm has been reviewed and upgraded, fixing several potential issues.
- The `header` parameter for the HTTP proxy type can now override original fields, including Host field.
- Added Gecko obfuscation support for Hysteria2, configured using the `gecko-password` parameter.
- All TLS proxy protocols now support customizing ALPN using the `alpn` field.
- When local DNS mapping is specified using server, multiple DNS servers can now be configured.
- URL scheme actions are now supported in Surge Mac. Check manual for more information.
- Enable the keep-alive mechanism for all QUIC-based protocols

### Other
- Optimize the performance of Surge Ponte.
- The UI configuration interface has been completed for the recently added proxy protocol parameters, including Tailscale.
- Fixed an issue where the `header` parameter did not take effect in HTTP/1.1 CONNECT mode.
- Fix some issues when using SF Symbols for policy group icons.
- Fixed compatibility issues between DoH3 and some servers.

### 5.19.0 — 2026-06-08

Adjustments to the Feature Update Subscription for Surge iOS

Since the introduction of the feature update subscription mechanism for Surge iOS, we have aimed to maintain a reasonable balance between continuously evolving the product’s capabilities and ensuring a reliable long-term user experience. After evaluation, we have decided to make the following adjustments:

1. All newly added proxy protocol compatibility support in the future will no longer be included within the scope of the feature update subscription, and will be available directly to all users.

2. TrustTunnel, which is currently supported on an experimental basis, will also not be subject to subscription restrictions and can be used directly.

We believe that protocol compatibility should be a fundamental capability provided in a stable, long-term manner, rather than a phased incremental feature. This means that, in the future, users will not need to worry about the availability of basic protocol support due to their subscription status; new protocol compatibility capabilities will also be made available to all users more directly and continuously.

After this adjustment, subscription updates will focus more on new advanced features, while protocol compatibility itself will be maintained as a long-term foundational capability of the product.

At the same time, the proxy protocol ecosystem itself is also constantly changing. Some protocols continue to evolve, while others gradually fall out of mainstream use cases. To ensure the long-term maintainability of Surge’s codebase and the overall quality of the product, we will also take actual usage into account when placing certain legacy protocols into maintenance freeze, or gradually ending support for them in the future.

We will handle related adjustments as cautiously as possible and provide explanations in advance, in order to minimize the impact on existing user profiles and user experience.

Thank you all for your continued support and feedback.

---------------------

* Added HTTP/2 CONNECT proxy support. You can configure HTTP/2-based CONNECT proxy connections via the h2-connect type.
* HTTP, HTTPS, HTTP/2 CONNECT, and TrustTunnel proxies now support custom request headers. 
* HTTP/2 CONNECT and the TrustTunnel proxy now support multiplexing. Because too many sub-connections multiplexed over the same TCP connection may cause performance issues, by default up to 3 sub-connections are allowed. This can be adjusted via the policy parameter `max-streams`.
* The storage logic for icon configuration in the iOS version has been adjusted. Now, when the profile is editable, it will preferentially be written into the profile to ensure interoperability with the Mac version. Only when the profile is read-only will a separate UI profile be used for storage.
* Fixed an issue where sending SNI did not strictly comply with RFC6066. Now, when an IP address is used as the hostname, the IP address will not be sent as SNI.
* Fixed an issue where crashes could occur when using ShadowTLS with certain servers.
* Fixed an issue where, when the Logbook contained a very large amount of data, it could not be viewed remotely via the Dashboard.
* Other performance optimization and minor enhancements.

### 5.18.0 — 2026-05-06

(Because the interval since the last subscription feature update was too long, all users whose subscription feature expiration date is after December 11, 2025 have been granted a free 3-month extension.)

New subscription feature: Logbook, used to persistently record various events that occur,
- Currently includes events such as engine start and stop, network switching, script start and stop, script timeout, etc.
- The logbook is specially optimized for script debugging, making it easy to view a script’s input, output, and logs. At the same time, scripts can proactively write content to the logbook using $surge.logbook("content")
- Surge Dashboard on Surge Mac can read the logbook content of remote Surge instances, and all script execution details can be accessed remotely

Other improvements
- Added support for the X25519MLKEM768 post-quantum hybrid key exchange group for all TLS-related features (such as proxy protocols, MITM, DoH/DoT/DoH3)
- Improved the $persistentStore management page, adding operations such as search, import/export, and delete all
- Refactored memory management for the QUIC protocol to resolve an issue where, under certain circumstances, QUIC-based protocols could experience sudden excessive memory usage that caused Surge to be terminated by the system
- Fixed a memory leak when using Trust Tunnel
- Fixed a crash that could occur with extremely low probability
- Fixed an issue where API requests could get stuck when HTTP API TLS is enabled
- Fixed some UI detail issues

### 5.17.1 — 2026-03-14

Added
- Experimental support for the Trust Tunnel protocol
- Added an Intent for profile switching; you can now switch the current Surge profile directly in Shortcuts
- Added a Debug message toggle on the Ponte page; when enabled, detailed connection status messages will be shown during the Ponte connection process
- Support for directly referencing hosted profiles without first adding the hosted profile as a local profile (i.e., the Linked Profile feature on macOS)
- Enterprise/Team license can now be used on the tvOS version

Improved
- All parameters for the throughput test are now customizable
- Added a workaround to address an issue on newer iOS versions where, after long scripts run for a while, setTimeout is throttled by the system’s resource saving and can fire at most once every 2 seconds
- Policy groups no longer validate the validity of sub-policy names. If a referenced sub-policy does not exist, the non-existent options will be automatically hidden at runtime. The include-other-group parameter has been adjusted similarly. Note: using a non-existent policy in [Rule] will still trigger a hard profile error prompt.

Fixed
- Fixed a compatibility issue between AnyTLS and some servers (when reuse is enabled, if a previous request fails, subsequent requests could hang)
- Fixed a rare crash when using QUIC-type protocols or h3 DNS
- Fixed an issue where only the small card view could display the “Update External Resources” menu item

## Apps similar to Surge 5

| App | Rating | Price | Category |
| --- | --- | --- | --- |
| [nRF Device Firmware Update](https://appshunter.io/ios/app/nrf-device-firmware-update/id1624454660) | 2.7 (9) | Free | Developer Tools |
| [Network Sniffer](https://appshunter.io/ios/app/network-sniffer/id6450956188) | 4.5 (184) | Free | Developer Tools |
| [Web Inspector](https://appshunter.io/ios/app/web-inspector/id1584825745) | 3.9 (149) | Free | Developer Tools |
| [Device Info Tool](https://appshunter.io/ios/app/device-info-tool/id6448629269) | 4.0 (4) | Free | Developer Tools |
| [Blink Shell, Build & Code](https://appshunter.io/ios/app/blink-shell-build-and-code/id1594898306) | 3.1 (414) | Free | Developer Tools |
| [Kodex](https://appshunter.io/ios/app/kodex/id1038574481) | 4.2 (207) | Free | Developer Tools |

## More apps by Surge Networks Inc.

- [iPerf - Speed Test Tool](https://appshunter.io/ios/app/iperf-speed-test-tool/id951598770)
- [Kuber - Kubernetes Dashboard](https://appshunter.io/ios/app/kuber-kubernetes-dashboard/id1461666739)
- [Elpass](https://appshunter.io/ios/app/elpass/id1488616799)

All apps by Surge Networks Inc.: https://appshunter.io/developer/1442620677

## Related topics

[surge](https://appshunter.io/ios/topics/surge) · [surge chaser](https://appshunter.io/ios/topics/surge-chaser) · [quantumult x](https://appshunter.io/ios/topics/quantumult-x) · [quantumult](https://appshunter.io/ios/topics/quantumult) · [loon](https://appshunter.io/ios/topics/loon) · [ftp network](https://appshunter.io/ios/topics/ftp-network) · [ieinspect](https://appshunter.io/ios/topics/ieinspect) · [sniffer](https://appshunter.io/ios/topics/sniffer) · [tudyahan 1874](https://appshunter.io/ios/topics/tudyahan-1874) · [request proxy](https://appshunter.io/ios/topics/request-proxy) · [hurricane electric network tools](https://appshunter.io/ios/topics/hurricane-electric-network-tools) · [http traffic](https://appshunter.io/ios/topics/http-traffic) · [brze vesti](https://appshunter.io/ios/topics/brze-vesti) · [pl nettools](https://appshunter.io/ios/topics/pl-nettools)

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-08-26.*
