ClearDeck
  • Intermediate
  • 7 min read
  • Updated 2026-10-09

Rule lists: the five modules and your own

What ships inside ClearDeck, how to import your own block and allow lists, and how link subscriptions stay up to date.

ClearDeck’s decisions come from modules — named rule lists. Five are built into the app, and you can add your own on top. This guide covers what is inside the box, how to import a list you already have, and how a link subscription keeps itself current.

What ships in the box

Every build of ClearDeck carries five modules, and all five are on by default:

Module 中文 Layer Entries
Ad blocking 广告拦截 Domain 81,143
Tracker blocking 行为跟踪拦截 Domain 121,037
Deep ad blocking 深度广告拦截 URL 1,597
Deep tracker blocking 深度跟踪拦截 URL 9,538
Malicious site blocking 恶意网址拦截 Domain 239,206
Total 452,521

The domain layer and the URL layer

The layer column matters more than it looks.

  • Domain modules match on the hostname. If a request goes to a host on the list, the connection is refused. This needs no extra setup and no certificate.
  • URL modules look at the full request path, not just the host. That is what lets ClearDeck block example.com/promo while still allowing example.com/article.

The catch: to see the path, ClearDeck has to read an encrypted request, and that is only possible with Deep inspection switched on and its certificate installed. Until then the two URL modules are enabled but idle — their card shows Paused / 已暂停 and offers a shortcut to turn deep inspection on. They still count in the total above; they simply cannot match anything yet. Deep inspection and the certificate covers the setup.

missing src/assets/shots/en/modules.png
Modules · the five bundled lists

Turning a module off

Each module has its own switch, and turning one off takes effect immediately: the domains it covers stop being blocked, so ads and trackers from that list can load again straight away. Because that is a real change to your protection, ClearDeck asks first. The dialog is titled, for example, Turn off "Ad blocking"?, and its body spells out that this list’s domains will no longer be blocked.

For the domain modules the app also states the scope plainly: Blocks this list's domains for every app. There is no per-app exception inside a bundled module.

My block & allow

My block & allow / 我的拦截与放行 is a card of its own, separate from the five bundles. Two things set it apart:

  • You build it yourself from Access log / 访问日志 entries. Open an app, expand its log, and tap Block / 拦截 or Allow / 放行 on a record. You then choose Apply to… / 应用到… — This app only / 仅这个应用 or All apps / 所有应用. The apps guide walks through it.
  • It is deliberately not switchable in one tap. The five bundles are one switch away from off; your own rules are not, because they are usually the considered ones.

When it is empty, the card says so:

Nothing here yet. Open an app, expand its access log and tap Block or Allow on a record — what you add shows up here.

Two rules of precedence are worth remembering:

  • Your rules outrank the bundled modules. If you have allowed a host, it is allowed even when a module would block it.
  • An allow beats a block on the same host. Allow always wins.

Import file

Import file / 导入文件 adds a list you already have on the phone. It accepts .yaml, .txt and .mrs.

missing src/assets/shots/en/import-file-dialog.png
Import file · type, action and entry count

After you pick a file, ClearDeck detects what kind of list it is — Domain list / 域名列表, IP list, Mixed list, or Full URL matching / 完整地址匹配 — and you choose whether it should block or allow. The confirmation dialog shows the type, the action and the entry count before anything is committed, so a file you did not mean to pick is easy to catch. One file can be up to 32 MB; larger ones are refused.

Import link / 导入链接 turns a URL into a refreshable module. Paste it in, and the list appears as a new module with its own one-tap Update / 更新 button and a Last updated: … line, so you can pull a newer copy whenever you want.

missing src/assets/shots/en/import-link.png
Import link · a refreshable module

One restriction is deliberate: only https:// links are accepted. A rule list is the firewall rule — a plaintext download could be rewritten in transit by anyone between you and the server, and the rewritten list would then be enforced on your phone. HTTPS means the list you receive is the list that was published. Updates run over HTTPS for the same reason.

A linked module updates only when you ask. It does not poll in the background, so importing a link does not by itself cost you data.

View list and the rule browser

Every module — bundled or imported — has View list / 查看名单. It opens a browser for that list:

  • a search box that matches a domain or a path,
  • a counter of the form N of M entries, showing how many entries match what you typed,
  • and a recently blocked links section, where each blocked request names the rule behind it with Matched rule: ….
missing src/assets/shots/en/module-detail-search.png
View list · search and matched rules

Where the lists come from

The bundled lists are assembled from well-known public sources: EasyList and EasyList Ad Servers for ads, EasyPrivacy and AdGuard Tracking Protection for trackers, 217heidai/adblockfilters and AWAvenue Ads Rule for both, and Hagezi Threat Intelligence Feeds (TIF, mini) for malicious sites. They are generated offline and committed with the source, so building ClearDeck never touches the network and the lists inside a given version are fixed and reproducible.

Next

This guide is also available in 简体中文

← All guides