What If a Browser Bypasses Clash Because of Its Own Proxy, DoH, or an Extension?

A browser can bypass the system proxy because of a proxy extension, built-in secure DNS, a developer-tools network proxy, a user profile, or an enterprise policy.

  • Proxy Modes and System Proxy
  • Troubleshooting
Short answer

Browsers can bypass the system proxy through proxy extensions, built-in secure DNS, Developer Tools network proxying, user profiles, or enterprise policy. Disable proxy extensions and secure DNS and return browser networking to Follow System Settings. As you restore each item, use the connection list to confirm whether requests appear.

Is an extension, DoH, or manual proxy overriding system settings?

Open the same site in a private window and watch the connection list. If the private window works, an extension or user profile is responsible; if every window fails, inspect DoH and enterprise policy.

  • Does the browser have proxy, rule, or privacy extensions installed?
  • Does the browser enable secure DNS, DoH, or custom DNS?
  • Is the browser proxy set to a manual proxy?
  • Do other browsers or private windows behave the same way?

Use a private window to restore the browser's default network path

  1. Test in a private window or a new browser profile first
  2. Disable browser proxy extensions and independent DoH
  3. Return browser proxy settings to Use System Proxy(See System Proxy FAQ)
  4. Check the Clash connection list to confirm that requests enter the client
  5. If only one browser is affected, reset that browser's network-related settings

Browser DoH can affect DNS routing decisions(See DNS FAQ)

A proxy extension can override the system proxy and PAC settings

Enterprise browser policy may prevent users from changing proxy or DNS settings