Open-source project
SukkaW/Surge avatar
SukkaW/Surge

Sukka Ruleset: Domain and IP Rule Sets for Surge, Mihomo, and sing-box

Rule Snippet & Rule Set for Surge / Mihomo (Clash.Meta) / Clash Premium (Dreamacro) / sing-box / Surfboard for Android / Stash

4,510 stars316 forksTypeScriptAGPL-3.0

At a glance

What is it?
Sukka Ruleset is a personally maintained, AGPL-3.0-licensed collection of domain and IP routing rule sets for Surge, Mihomo, Clash Premium, sing-box, Surfboard, and Stash. It emphasizes correct DNS leak prevention through a strict rule ordering requirement and covers ad blocking, phishing protection, and CDN routing.
Who is it for?
Sukka Ruleset is a well-organized, actively updated collection for users of proxy tools who need comprehensive domain-level routing with DNS leak protection. The AGPL-3.0 license means any distributed modification must also be released under AGPL-3.0.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Sukka Ruleset Covers and Who Uses It

Proxy tools like Surge, Mihomo, sing-box, and Surfboard route network traffic based on rule lists. Each rule matches a domain or IP range and assigns it to a proxy policy or a direct connection. A user who wants to block ads, bypass tracking domains, protect against phishing, and route CDN traffic efficiently needs rule lists covering all of those categories.

Sukka Ruleset is a personal collection by Sukka, gathered and maintained for exactly those purposes. The README states clearly that these are personal rules maintained for personal use. The collection covers six proxy platforms: Surge (Mac, iOS, tvOS), Mihomo (Clash.Meta), Clash Premium (Dreamacro), sing-box, Surfboard for Android, and Stash.

Each platform receives its rules in the format it expects. Surge uses .conf files with RULE-SET and DOMAIN-SET directives. Mihomo uses YAML rule-providers. sing-box receives its rules in Headless Rule format. The repository builds all of these from TypeScript source files in the Build/ directory, and the built rules are served from ruleset.skk.moe on Cloudflare.

The last push to the repository was on 2026-09-26, reflecting ongoing maintenance.

The domainset/non_ip/ip Architecture and DNS Leak Prevention

Sukka Ruleset divides rules into three categories for each platform: domainset, non_ip, and ip. This division is not cosmetic; it is a performance and security requirement.

Domain rules (domainset and non_ip) match by hostname and do not require the proxy tool to resolve the domain to an IP address first. IP rules (ip) require a DNS lookup before matching. Proxy tools process rules in the order they appear in the configuration file and perform DNS resolution only when an ip rule, a FINAL rule, or a direct policy is reached.

The README is explicit: all domainset and non_ip rules, including any custom DOMAIN, DOMAIN-SUFFIX, and DOMAIN-KEYWORD rules added by the user, must be placed before all ip rules, IP-CIDR, IP-CIDR6, IP-ASN, and GEOIP rules. There are no exceptions. Placing a single ip rule above a non_ip rule causes the proxy tool to resolve the domain before the non_ip rule fires. Since the domain being resolved is a domain that should be proxied, the DNS query goes out through the local resolver, and that local resolver is typically GFW-poisoned for exactly those domains. The DNS protection that the entire ruleset provides is then gone.

For Surge, the README gives example rule snippets. The ad-blocking rules appear in this order: DOMAIN-SET for the base block list, then RULE-SET for additional categories, then the ip block list last.

Adding Ad-Blocking and Phishing Rules to Surge

For Surge, the basic ad-blocking and phishing configuration looks like this:

ini
RULE-SET,https://ruleset.skk.moe/List/non_ip/reject-drop.conf,REJECT-DROP,pre-matching
DOMAIN-SET,https://ruleset.skk.moe/List/domainset/reject.conf,REJECT,extended-matching
DOMAIN-SET,https://ruleset.skk.moe/List/domainset/reject_extra.conf,REJECT
RULE-SET,https://ruleset.skk.moe/List/non_ip/reject.conf,REJECT,extended-matching

The IP-based reject rule must come after all domain rules:

ini
RULE-SET,https://ruleset.skk.moe/List/ip/reject.conf,REJECT-DROP

For Mihomo, the same category uses YAML rule-providers with an HTTP type and a 43200-second (12-hour) update interval. The reject rules are declared in the rule-providers section and referenced in the rules section using RULE-SET entries.

yaml
rule-providers:
  reject_non_ip_no_drop:
    type: http
    behavior: classical
    format: text
    interval: 43200
    url: https://ruleset.skk.moe/Clash/non_ip/reject-no-drop.txt
    path: ./sukkaw_ruleset/reject_non_ip_no_drop.txt

The README documents the full set of categories: basic block (about 120,000 domains), extra block (about 90,000 supplementary domains), and phishing (about 130,000 domains). The README recommends against enabling the phishing list on mobile platforms due to performance, suggesting ADGuard for Android or iOS for those environments.

Platform Coverage and the Input Method Telemetry Rule

The ruleset covers six proxy platforms with different rule format requirements. Surge receives three types: DOMAIN-SET files in /List/domainset/, RULE-SET files in /List/non_ip/, and RULE-SET files in /List/ip/. Mihomo receives domain and text format rules in /Clash/domainset/ and /Clash/non_ip/, and classical and ipcidr rules in /Clash/ip/.

Clash Premium (the legacy Dreamacro fork) shares the Mihomo domainset format but has separate directories for its non-domainset rules. sing-box receives Headless Rule format files for all three categories. Surfboard for Android shares the Surge domainset format and has its own non_ip and ip directories.

Beyond ad blocking, the ruleset includes a manually maintained rule for the Sogou input method (sogouinput.conf). The README explains the motivation: Sogou sends every character typed to domains like get.sogou.com/q. This rule blocks those transmissions. The trade-off is that it also blocks Sogou account sync, dictionary updates, and feedback submission. For Surge: RULE-SET,https://ruleset.skk.moe/List/non_ip/sogouinput.conf,REJECT.

Speedtest routing is also covered, with rules for speedtest.net test points and macOS netQuality. The README notes that fast.com shares infrastructure with Netflix CDN, so it is intentionally excluded from the speedtest rule to avoid breaking streaming routing.

Serving the Ruleset and the Mirror Setup

The canonical server is ruleset.skk.moe, which is Cloudflare-powered. The README notes that Cloudflare's nodes have inconsistent speed and stability in mainland China, which is why a mirror is provided.

The official mirror is ruleset-mirror.skk.moe, maintained by Sukka. The README also lists two Git repositories that can be used to synchronize rules for self-hosted mirrors: one on GitHub (SukkaLab/ruleset.skk.moe) and one on GitLab (SukkaW/ruleset.skk.moe).

Users who want to build the rules themselves can use the TypeScript source in the Build/ directory. The package.json shows the build command as pnpm run node ./Build/index.ts, using @swc-node/register for TypeScript execution. The build system fetches upstream data, applies filters, and writes the output rule files.

The repository's package.json includes a substantial set of dependencies for the build process: @ghostery/adblocker for parsing filter lists, tldts for domain parsing, hntrie for domain trie operations, fast-cidr-tools for IP range operations, and undici for HTTP fetching. None of these are runtime dependencies for the ruleset consumers; they are build-time tools.

License: AGPL-3.0 with One CC BY-SA Exception

The project uses AGPL-3.0 for almost everything. The exception is List/ip/china_ip.conf, which is licensed under CC BY-SA 2.0.

AGPL-3.0 is a copyleft license with a network use clause. If you distribute a modified version of the rules, or run a modified version as a network service, you must make the source of your modifications available under AGPL-3.0. Users who fetch the prebuilt rules from ruleset.skk.moe and use them without modification are unaffected by this requirement since they are not distributing anything.

CC BY-SA 2.0 is a share-alike license: redistributions of the china_ip.conf file must carry the same license and credit the original source. The README does not name the original source of the china_ip.conf data.

Commercial proxy service operators who include Sukka Ruleset in their service should note that AGPL-3.0 applies to any modifications. The README also warns specifically about this scenario: some commercial proxy service terms of service state that using third-party rule files automatically waives the user's SLA and technical support rights.

How Sukka Ruleset Compares to EasyList

EasyList is the most widely used ad-blocking filter list in the world. Browser extensions like uBlock Origin and AdGuard for browser use it to block requests at the HTTP layer inside the browser. EasyList works by inspecting HTTP requests as the browser makes them and blocking those that match the filter rules.

Sukka Ruleset operates at a different layer: the proxy tool intercepts TCP connections before the browser sees them, routing them based on domain names and IP ranges. This means Sukka Ruleset blocks a tracked domain for every application on the device, not only the browser. A mobile app that phones home to an ad network is blocked the same way a browser request is.

The trade-off is scope. EasyList contains detailed cosmetic filters that hide ad elements on specific websites, removing the empty space left by blocked requests. Sukka Ruleset has no cosmetic filtering. It either routes a domain through a policy or it does not. For users who want cosmetic filtering in their browser, EasyList (via a browser extension) and Sukka Ruleset (at the proxy layer) are complementary rather than substitutes.

Editorial conclusion

Sukka Ruleset is a well-organized, actively updated collection for users of proxy tools who need comprehensive domain-level routing with DNS leak protection. The AGPL-3.0 license means any distributed modification must also be released under AGPL-3.0. The china_ip.conf file carries a separate CC BY-SA 2.0 license. Users who consume the rules from ruleset.skk.moe without modification are unaffected by the AGPL distribution requirement. The strict domainset/non_ip/ip ordering is not optional: misplacing an ip rule above a non_ip rule silently disables the DNS protection the entire ruleset is designed to provide. Verify the rule ordering in your configuration file against the README before deploying.

Frequently asked questions

How do I add Sukka Ruleset ad-blocking rules to Surge?

Add the DOMAIN-SET and RULE-SET lines from the reject section of the README to your Surge configuration, placing them before any ip rules. The base block list uses DOMAIN-SET pointing to /List/domainset/reject.conf with the REJECT action.

What is the difference between non_ip and ip rule sets in Sukka Ruleset?

Non_ip rules match on domain names and do not trigger a DNS lookup. IP rules match on IP ranges or ASN and require the proxy to resolve the domain first. The README requires all non_ip and domainset rules to be placed before any ip rules to prevent DNS leaks to GFW-poisoned resolvers.

Does the AGPL-3.0 license affect users who only fetch rules from ruleset.skk.moe?

No. AGPL-3.0 applies to distribution and network deployment of modified source code. Users who fetch the prebuilt rules from ruleset.skk.moe and use them without modification are not distributing or modifying the source, so the copyleft obligation does not apply to them.

Official sources

  1. Issues
  2. License: AGPL-3.0
  3. Project website
  4. README
  5. SukkaW/Surge on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/sukkaw-surge.svg)](https://hysenlabs.com/projects/sukkaw-surge)