Skip to content

Outbounds ​

outbounds is the array of upstream targets. Each entry is a flat object: the type / tag envelope plus the selected type's own fields at the same level. There is no "first outbound is default" rule — unmatched traffic goes to route.final.

Envelope ​

FieldTypeDefaultAllowed valuesDescription
typestring—direct | bridge | block | selector | urltest | socks | http | shadowsocks | snell | vmess | trojan | naive | tor | ssh | shadowtls | vless | anytls | hysteria | tuic | hysteria2Outbound type. Selects which option struct the rest of the object is decoded into. An unregistered value fails at startup with "unknown outbound type".
tagstring——Unique name for this outbound. Referenced by route rules, route.final, group outbounds and dialer detour.

Source: option/outbound.go:22-26 · pinned at v1.14.2 (af6e64c)

Per-type fields are documented on the protocol pages: Direct, HTTP & SOCKS, Shadowsocks, VMess, Trojan, Naive, Tor, SSH, VLESS, AnyTLS, Hysteria2, TUIC. selector and urltest are group outbounds that pick among other tags. bridge and snell are documented on Bridge and Snell.

Shared dial fields (DialerOptions) ​

Every dialing outbound embeds DialerOptions — detour plus the fields of AbstractDialerOptions (a separate struct so the direct route rule action can reuse the dial fields without detour). All of them sit at the same flat level as the envelope.

FieldTypeDefaultAllowed valuesDescription
detourstring——Dial through another outbound, addressed by its tag. When set, all other dial fields are ignored.

Source: option/outbound.go:80-83 · pinned at v1.14.2 (af6e64c)

FieldTypeDefaultAllowed valuesDescription
bind_interfacestring——Network interface to bind outgoing connections to.
inet4_bind_address*badoption.Addr——IPv4 source address to bind.
inet6_bind_address*badoption.Addr——IPv6 source address to bind.
bind_address_no_portboolfalsetrue | falseSet IP_BIND_ADDRESS_NO_PORT when binding — delays port allocation until connect. Linux only.
protect_pathstring——Unix socket path of an Android VpnService protect daemon; each socket fd is sent there before dialing.
routing_markFwMark——SO_MARK (fwmark) to set on outgoing sockets. Linux only.
reuse_addrboolfalsetrue | falseSet SO_REUSEADDR on outgoing sockets.
netnsstring——Network namespace to dial from: a name or path, or the tag of a top-level network_namespaces entry. Linux only. Avoid referencing an unshare namespace — its only route out is sing-box's own TUN.
connect_timeoutbadoption.Duration——TCP connect timeout. Duration string, e.g. "5s".
tcp_fast_openboolfalsetrue | falseEnable TCP Fast Open for outgoing connections.
tcp_multi_pathboolfalsetrue | falseEnable Multipath TCP for outgoing connections.
disable_tcp_keep_aliveboolfalsetrue | falseTurn TCP keep-alive off for outgoing connections.
tcp_keep_alivebadoption.Duration——Keep-alive idle period before probes start. Duration string.
tcp_keep_alive_intervalbadoption.Duration——Interval between keep-alive probes. Duration string.
udp_fragment*boolfalsetrue | falseAllow fragmenting UDP packets larger than the MTU instead of dropping them.
domain_resolver*DomainResolveOptions——Which DNS server (by tag) resolves the server address, either a plain tag string or an object with per-dial overrides (server, strategy, timeout, disable_cache, disable_optimistic_cache, rewrite_ttl, client_subnet). For direct it resolves the requested domain instead.
network_strategy*NetworkStrategy——Strategy for picking among available networks (e.g. default / hybrid / fallback). Platform builds with network awareness only.
network_typebadoption.Listable[InterfaceType]——Preferred network types (wifi, cellular, ethernet, other) when network_strategy is used.
fallback_network_typebadoption.Listable[InterfaceType]——Network types to fall back to when the preferred ones are unavailable.
fallback_delaybadoption.Duration——Wait before starting the fallback dial (Happy-Eyeballs style). Duration string, e.g. "300ms".
domain_strategyDomainStrategy—prefer_ipv4 | prefer_ipv6 | ipv4_only | ipv6_onlyDeprecated in favour of domain_resolver.strategy: setting it aborts startup unless the environment variable ENABLE_DEPRECATED_LEGACY_DOMAIN_STRATEGY_OPTIONS=true is set.

Source: option/outbound.go:85-112 · pinned at v1.14.2 (af6e64c)

Shared server fields (ServerOptions) ​

Protocol outbounds that connect to a fixed server embed ServerOptions.

FieldTypeDefaultAllowed valuesDescription
serverstring——Server host name or IP.
server_portuint16——Server port.

Source: option/outbound.go:183-186 · pinned at v1.14.2 (af6e64c)

Minimal example ​

json
{
  "outbounds": [
    {
      "type": "shadowsocks",
      "tag": "proxy",
      "server": "example.com",
      "server_port": 8388,
      "method": "2022-blake3-aes-128-gcm",
      "password": "<base64-key>"
    },
    { "type": "direct", "tag": "direct" }
  ],
  "route": { "final": "proxy" }
}

Notes ​

  • There is no dns outbound — configuring one is an error; DNS hijacking is a rule action. There is no wireguard outbound either: use a WireGuard endpoint instead.
  • shadowsocksr is registered only as a stub that errors (sing-box has no ShadowsocksR implementation). hysteria, tuic and hysteria2 require a with_quic build, and the naive outbound a with_naive_outbound build; official release binaries include both, except with_naive_outbound on a few less common platforms.
  • detour chains outbounds by tag; a chain that reaches itself is a startup error.
  • When server is a domain, it is resolved with domain_resolver, falling back to route.default_domain_resolver. Both may be omitted only when a single DNS server is configured; otherwise startup fails.
  • bridge is the L3 counterpart of direct: it forwards L3 connections (TCP, UDP, ICMP) from a TUN or other L3 endpoint straight out of a network interface and rejects L4 connections. It requires privileges (Linux, macOS, Windows, rooted Android, jailbroken iOS) and is fed by a route action in pre-match.
  • snell implements Surge's Snell protocol for both inbound and outbound, without the v5 QUIC proxy mode.

Cross-core notes ​

  • Xray-core nests protocol fields in settings, chains outbounds with streamSettings.sockopt.dialerProxy (proxySettings is rejected at startup), and treats the first array entry as the default route target. See Xray Outbounds.
  • mihomo calls these proxies, with group types (select, url-test, fallback, load-balance) as separate proxy groups rather than outbound types.

Source: option/outbound.go:22-26 · v1.14.2 (af6e64c)

Core Tutorial by Argsment