This Android VPN guide looks beyond short speed tests to answer the questions that matter every day: whether the client disconnects in the background, how to handle battery restrictions, and whether only selected apps can use the proxy. We test v2rayNG, NekoBox for Android, Hiddify, Clash Meta for Android, and sing-box Android. All are clients that require a valid subscription configuration or a self-managed node.
Android clients may appear to offer only three actions—import, connect, and disconnect—but the real differences lie in core versions, routing rules, DNS handling, and system integration. The same route can behave differently across clients. The cause may be domain resolution, an app being excluded from the VPN interface, or the device manufacturer stopping the client in the background—not necessarily transfer speed.
Three practical factors when choosing an Android client
Background reliability depends on more than the client
Android passes app traffic to the client through the system VPN interface. A key or VPN status indicator confirms that the interface is established, but not that the client can keep running in the background. Pixel-like devices with near-stock Android are usually affected mainly by battery optimization; Samsung, Xiaomi, and other devices may also add app sleeping, auto-start restrictions, and background activity controls.
So whether a client disconnects cannot be judged separately from system settings. A more reliable approach is to allow background activity, set the battery policy to unrestricted, and make sure the system has not placed the client in a sleep list. If the system offers Always-on VPN, enable it only after ordinary connection testing is complete. Always-on VPN can help the system restart a connection, but it cannot fix an invalid subscription, an unavailable node, or conflicting DNS settings.
Per-app proxying: include or exclude
Per-app proxying usually follows one of two approaches: send only selected apps through the VPN, or send everything through it by default and exclude apps that do not need the proxy. The first keeps the scope clear and works well for browsers, Streaming, or AI Tools. The second is less likely to miss newly installed apps, but local services, LAN control tools, and apps sensitive to network conditions may need to be excluded manually.
After choosing a mode, check DNS as well. Even when app traffic uses the proxy, unsuitable local resolution can cause domain failures, inconsistent regional results, or indirect routing. “Remote DNS,” “proxy DNS,” and Android Private DNS are not the same switch under different names. Avoid overlapping forced policies that override one another.
Protocol support depends on the core, not the interface
Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different proxy protocols or transport options. Shadowsocks is relatively straightforward to configure; VMess and VLESS are common in the Xray ecosystem; Trojan is often paired with TLS; Hysteria2 and TUIC use QUIC and depend more heavily on UDP quality. An interface showing a node name does not mean its current core can establish the corresponding connection.
If a subscription imports successfully but every node fails, first check the node protocols and then whether the client core is outdated. If only Hysteria2 or TUIC routes fail, verify that the current network does not restrict UDP. Repeatedly refreshing the subscription will not usually fix core incompatibility or transport restrictions.
Five Options Tested Side by Side
| Client | Key strengths | Per-app support | Best for | Watch-outs |
|---|---|---|---|---|
| v2rayNG | Straightforward subscription imports with broad Xray protocol coverage | Supports including or excluding apps | Users who need common protocols such as VLESS, VMess, and Trojan | Many advanced routing options; core version affects compatibility with newer protocols |
| NekoBox for Android | Built on the sing-box ecosystem, with extensive protocol and routing options | Supports app-level selection and routing rules | Users combining multiple protocols who are comfortable reviewing detailed settings | High option density; first-time setup requires understanding how DNS and routing interact |
| Hiddify | Centralized configuration import and node switching in a beginner-friendly interface | Offers split routing and app selection | Users who want to change fewer parameters and establish a stable connection first | Complex rules are less visible than in rule-focused clients |
| Clash Meta for Android | Strong support for rule sets, policy groups, and subscription configuration | Can combine app and rule-based controls | Users with existing Clash configurations who rely on policy-group switching | Check maintenance status and the installation source separately; do not download packages from untrusted pages |
| sing-box Android | Clear configuration structure for fine-grained routing and newer protocols | Can be controlled through routing and app rules | Users who understand configuration files and want consistent desktop and Android logic | Writing configurations has a steep learning curve, and ordinary subscriptions may not express every requirement directly |
v2rayNG: A dependable entry point for common subscriptions
v2rayNG makes subscription imports clear and manual addition of VLESS, VMess, Trojan, and Shadowsocks nodes convenient. For users who only need to choose a node, connect, and configure per-app proxying, its feature boundaries are easy to understand. App-level proxying can use bypass mode or proxy-only-selected-apps mode. After changing the list, disconnect and reconnect so the system VPN interface is rebuilt with the new selection.
The main challenge is its advanced options. When routing, DNS, domain policies, and core settings are changed together, the source of an error is difficult to identify. Start with the default configuration to verify the node, then enable split routing one setting at a time. If the subscription includes Hysteria2 or TUIC, check current core support instead of relying on the node name alone.
NekoBox for Android: Protocols and routing first
NekoBox is a good fit when a subscription contains several types of nodes. Its sing-box capabilities are presented comprehensively, with more granular app routing, DNS, and outbound selection. In testing, the key issue was not the connect button but rule priority: when app rules, domain rules, and the default outbound all apply, an earlier match can prevent later rules from taking effect.
If the goal is simply to proxy a small number of apps, start with app selection rather than importing a complex rule set. Once the basic connection is stable, add direct LAN access, direct access for specific domains, or remote DNS. This makes it easier to determine whether a problem comes from the node, app scope, or domain rules instead of troubleshooting an entire configuration at once.
Hiddify: Less initial configuration overhead
Hiddify puts configuration import, node selection, and connection status in a relatively clear interface. It suits users who want to establish a working connection first and refine details later. It still offers split routing and app selection without requiring users to understand full rule syntax from the start. When subscription formats come from varied sources, check which node types were actually recognized after importing.
If an app does not use the proxy as expected, do not switch every route immediately. First confirm whether the app is in the include list, then check whether the selected mode is “proxy selected apps only” or “bypass selected apps.” The lists can contain exactly the same apps while producing opposite results—a common Android configuration mistake.
Clash Meta for Android: Familiar for policy-group users
The core value of a Clash configuration is its rule groups and policy groups. A subscription can group nodes by purpose and then match domains, IP addresses, or apps to different policies. For people who already maintain rule files, this is more flexible than selecting apps one by one. For newcomers to Android clients, it can also create the misconception that a selected node is not being used because the rules send traffic to another policy.
Maintenance status also deserves attention. An old package may continue to run without supporting later core changes. If you keep using it, verify the version and checksum on the trusted project page. If you are installing for the first time and do not depend on a Clash configuration, there is no need to choose an unclear build just for its rule features.
sing-box Android: For precise configuration control
sing-box Android is closer to a configuration-first solution. It suits users who need to specify inbound and outbound settings, DNS servers, and routing conditions, and it makes it easier to carry similar configuration logic to other platforms. The trade-off is that troubleshooting requires reading the configuration structure. Subscription conversion results must also be checked; do not assume a converter preserves every meaning in the original configuration.
For general users, prioritize configuration formats explicitly supported by the client and avoid converting through several tools in succession. Each conversion can lose policy groups, node parameters, or DNS rules. If conversion is necessary, keep the original subscription and separately verify node connectivity, domain resolution, and per-app behavior in the new configuration.
Background reliability and battery settings
A background disconnect is easy to mistake for a route problem. Check whether it consistently happens after locking the screen, leaving the device idle, or system app cleanup. If the connection works in the foreground but the status indicator disappears in the background, address system permissions first. If the indicator remains but websites stop loading, the more likely causes are the node, DNS, or a network transition.
- Establish a basic connection first. Temporarily disable custom split routing and complex DNS. Import the subscription, choose an available node, and connect.
- Adjust the battery policy. Open the system battery settings for apps and set the client you use to allow background activity or remain unrestricted.
- Check the manufacturer’s background controls. Confirm that the client is not in a sleep, deep-sleep, or automatic cleanup list. On systems with auto-start management, allow it to resume running.
- Enable Always-on VPN last. Turn on the system option only after the basic connection is stable, so an incorrect configuration does not keep reconnecting and make troubleshooting difficult.
- Add per-app and DNS rules last. Change one category of settings at a time, reconnect, and check the result to make conflicts easier to identify.
- ✅ The VPN status indicator remains after the screen is locked, and returning to the foreground does not require tapping Connect again.
- ✅ After switching from Wi-Fi to mobile data, the client restores the tunnel and completes domain resolution again.
- ✅ After editing the per-app list, you reconnected and the target and excluded apps behave as expected.
- ❌ You only kept the client in recent apps without adjusting battery optimization or sleep policies.
- ❌ You enabled several forced DNS options at once and kept changing nodes after resolution failed.
How to check per-app proxying and DNS leaks
Checking per-app proxying is not just about the public exit address. First confirm that the target app enters the system VPN interface, then check domain resolution, and finally verify the exit route. Some apps cache connections or DNS results, so after changing rules, fully stop the app process and reopen it. If an app supports QUIC, it may continue reusing an old connection; seeing the old exit briefly does not necessarily mean the new rule failed.
A DNS leak generally means that domain queries that should be handled through the proxy are instead sent to the local network resolver. It does not necessarily mean browsing content is directly exposed, but it makes the domain request path inconsistent with the proxy exit. Android Private DNS uses encrypted resolution; clients may also provide local DNS, remote DNS, Fake IP, or rule-based DNS. More layers are not automatically safer—the key is consistency between query results and routing policies.
A useful troubleshooting order is to let the client take control of DNS first, send domains that require the proxy to a remote resolver, and leave LAN names and explicitly direct domains to local resolution. If you use Fake IP, confirm that the client and rule set can restore domain names correctly, and watch for LAN apps that do not support Fake IP. If an app opens an IP address but not a domain, check DNS first rather than continuing to switch transport protocols.
Split-routing rule priority
App-level rules decide which apps enter the tunnel; domain and IP rules decide which outbound route they use afterward. Both layers can work together, but keep the logic simple. For example, add only the browser to the VPN, then send LAN and mainland-China resources directly while routing everything else through the proxy. If the app itself is excluded, later domain rules usually cannot take over its traffic.
Rule sets also need updates. When domain categories and IP data become outdated, requests that should go direct may be sent through the proxy, and vice versa. A subscription refresh usually updates nodes, not necessarily the client core or rule data, so an “updated subscription” does not prove that every component is current.
How to choose for different use cases
You want stable use after importing a subscription
Start with v2rayNG or Hiddify. The former suits common Xray protocols and clear app selection; the latter is better for users who want a centralized interface and fewer initial settings. Whichever you choose, complete the basic test with the default DNS and routing first. Do not import rule sets, change the core, and enable strict mode all before the first connection.
You need precise per-app routing
v2rayNG, NekoBox, and Hiddify can all handle app-level selection. Focus on which operating style feels natural: when only a few apps are involved, “include only” is clearer; when most apps should use the proxy by default, “exclude” requires less maintenance. NekoBox is a good choice if you want to add domain and outbound rules beyond app selection.
You already have a Clash policy-group configuration
You can continue with the Clash Meta for Android approach because its policy-group names, rule order, and node-selection workflow are familiar. However, include the client’s maintenance and installation source in the decision instead of checking only whether the old configuration imports. If you plan to reorganize the setup, you can also migrate to NekoBox or sing-box Android and verify DNS, policy groups, and outbound behavior line by line.
You need Hysteria2, TUIC, or complex routing
NekoBox and sing-box Android deserve priority consideration. Both suit users who understand protocol parameters and routing structures, but “support” still depends on the actual core version. QUIC-based protocols may fail on networks that restrict UDP. Switching to another route of the same type is unlikely to help; compare with a permitted transport instead.
Final choice and pre-installation checks
Considering background reliability, per-app proxying, and protocol compatibility, v2rayNG is a good starting point for common subscriptions; Hiddify reduces configuration overhead; NekoBox suits users who want newer protocols and fine-grained routing; sing-box Android fits users who can maintain structured configurations; Clash Meta for Android is best for people who already depend on policy groups and can verify its maintenance status.
The client only executes the configuration. Route quality still depends on the node, access network, and transport method. IEPL private links usually carry the cross-border segment over carrier or enterprise-grade paths, unlike public direct routes. A relay route connects to a relay entry point before reaching the exit; a direct route accesses the remote node from the local network. A private link is not always faster, and a relay is not necessarily slower. Choose based on the entry region, peak network conditions, and target service.
Before installing, also verify the download source, configuration backup, and subscription security. Subscription links usually contain the credentials required to access nodes. Do not paste them publicly into web conversion services or send them to unrelated people. If a link is exposed, reset it in the service panel instead of merely deleting it from the client. When changing clients, keep the old configuration until the new client has passed connection, DNS, and per-app checks.
- ✅ Get the client from the project’s official release page or a trusted app channel.
- ✅ Confirm that the subscription format is compatible with the target client before importing.
- ✅ Verify the basic connection before enabling per-app proxying and custom DNS.
- ✅ Save the original subscription and essential configuration so you can restore them if migration fails.
- ❌ Submit the subscription link to an online conversion page from an unknown source.
- ❌ Replace the client, protocol, DNS, and all rules at once because of a single disconnect.