Built-in outbounds
Rules can use DIRECT for direct access and REJECT to refuse connections without server credentials.
yaml
rules:
- DOMAIN-SUFFIX,blocked.example,REJECT
- MATCH,DIRECTDefine a named node for extra settings. Type values are lowercase:
yaml
proxies:
- name: Direct-IPv4
type: direct
ip-version: ipv4
- name: Internal-DNS
type: dnsDirect connects to the destination itself. DNS sends DNS requests to the internal resolver; it cannot carry ordinary website traffic. Configure resolvers under DNS.
Match rules again
Rematch can attach a name and restart matching, or enter a named sub-rule through target-sub-rule. This example marks example.com traffic and then routes it directly:
yaml
proxies:
- name: Mark-Work
type: rematch
target-rematch-name: work
rules:
- REMATCH-NAME,work,DIRECT
- DOMAIN-SUFFIX,example.com,Mark-Work
- MATCH,DIRECTHandle the mark before the triggering rule to prevent loops. Ordinary routing can use direct rules without a rematch layer.
Reference: mihomo.