- Advanced
- 8 min read
- Updated 2026-10-09
Deep inspection and the certificate
What deep inspection adds, why it needs a certificate on your phone, how to install and remove it, and the honest limits of the technique.
Deep inspection is the most invasive thing ClearDeck does, and most people do not need it. This guide says plainly what it adds, why it asks for a certificate, and what installing one really means.
What it adds
Without it, the firewall can judge a connection only by its hostname. Usually
that is enough: a request to ads.example.net is a request to that host, full
stop.
But a hostname is coarse. One host can serve both what you want and what you do
not: news.example.com/article and news.example.com/promo share a hostname, so
a domain rule has to take both or neither. Deep inspection reads the full
request path, so it can block /promo while allowing /article on the same
host.
It is also what the two URL modules need. Deep ad blocking and Deep tracker blocking (1,597 and 9,538 entries) have nothing to match against until deep inspection is on — before that they show as Paused. Those two lists are covered in rule lists.
Why a certificate is needed
Requests inside apps are encrypted, so by default ClearDeck cannot read the path — it can see only the hostname. Installing ClearDeck’s certificate lets the phone hand those requests to ClearDeck for inspection, so it can look at the path before deciding.
To be plain about it: the certificate stays on this phone and is never uploaded. It is what lets your own device examine your own traffic. It is not a key to anything on a server.
Installing the certificate
The app walks you through it. On the Certificate card, tap Install certificate / 安装证书, then follow the two steps:
- Tap Install certificate. The file is saved to the Downloads folder and the phone’s certificate screen opens automatically.
- Choose Install certificate → CA certificate → Install anyway, then
pick
cleardeck-ca.crt. The system will warn that the certificate is not from a trusted source — that warning is expected, because it is ClearDeck’s own certificate.
Until the certificate is installed, the screen says so directly: Not working yet: the ClearDeck certificate is not installed. The switch can be on and deep inspection still will not work — the certificate is the part that matters.
Removing it
To uninstall, open the phone’s Trusted credentials → User tab, find ClearDeck and remove it. Removing the certificate turns deep inspection off, and nothing else changes: the bundled domain lists and your own rules keep working exactly as before.
The app offers View or remove certificate / 查看或移除证书 to take you to the right screen.
Scope controls
Once a user certificate is installed, you should decide what it gets to see. Three controls do that.
Which apps / 选择应用
All apps, or Only the apps I pick. The picker is searchable and shows how
many you have chosen (N selected). Apps you leave out are untouched: their
traffic is never exposed to deep inspection. This is the single most useful
control — pick the browser you actually use, and leave the banking app out.
Wi-Fi only / 仅 Wi-Fi
On, deep inspection switches itself off on mobile data automatically. Decrypting and inspecting costs battery and data throughput, and on cellular both matter more, so this is a sensible default. Off, it runs on whatever connection you have.
Content inspection limit / 内容检查上限
Choose 128 KB, 256 KB, 512 KB or 1 MB; the default is 256 KB. ClearDeck inspects a request only up to this much of its content — anything larger passes through without being read word by word.
The trade-off runs both ways:
- Larger inspects more of each file, so it is likelier to catch an ad buried in a big response, but it holds more content in memory while checking.
- Smaller uses less memory and less power, but may miss an ad that appears only deep inside a large file.
256 KB is a reasonable middle. Reach for 1 MB only when you are chasing one specific annoyance; drop to 128 KB on an older or low-memory phone.
The three states
The app reports deep inspection in three states:
| State | Meaning |
|---|---|
| On / 开启 | Deep inspection is running. |
| Off / 未开启 | It is switched off. |
| Paused / 已暂停 | Power saving is on and has paused deep inspection. |
Paused is not a fault. Power saving intentionally pauses deep inspection to save battery; turn power saving off and deep inspection comes back on its own. If the URL-layer modules are showing Paused as well, that is the same thing seen from the Modules tab.
Should you turn it on?
Usually, no — and ClearDeck does not ask you to.
The five bundled lists and the domain layer block the large majority of ads and trackers with no certificate, no decryption, and nothing installed on your device. Deep inspection adds path-level matching and the two URL modules on top, and it costs you a certificate that can read decrypted traffic. If precise URL rules are what you have been missing, it is worth it. If not, leave it off — the app works fully without it.
Next
- Rule lists: the five modules and your own — the two URL modules deep inspection unlocks
- Power saving — why deep inspection can show as Paused
This guide is also available in 简体中文