- Intermediate
- 7 min read
- Updated 2026-10-09
Rule lists: the five modules and your own
What ships inside ClearDeck, how to import your own block and allow lists, and how link subscriptions stay up to date.
ClearDeck’s decisions come from modules — named rule lists. Five are built into the app, and you can add your own on top. This guide covers what is inside the box, how to import a list you already have, and how a link subscription keeps itself current.
What ships in the box
Every build of ClearDeck carries five modules, and all five are on by default:
| Module | 中文 | Layer | Entries |
|---|---|---|---|
| Ad blocking | 广告拦截 | Domain | 81,143 |
| Tracker blocking | 行为跟踪拦截 | Domain | 121,037 |
| Deep ad blocking | 深度广告拦截 | URL | 1,597 |
| Deep tracker blocking | 深度跟踪拦截 | URL | 9,538 |
| Malicious site blocking | 恶意网址拦截 | Domain | 239,206 |
| Total | 452,521 |
The domain layer and the URL layer
The layer column matters more than it looks.
- Domain modules match on the hostname. If a request goes to a host on the list, the connection is refused. This needs no extra setup and no certificate.
- URL modules look at the full request path, not just the host. That is what
lets ClearDeck block
example.com/promowhile still allowingexample.com/article.
The catch: to see the path, ClearDeck has to read an encrypted request, and that is only possible with Deep inspection switched on and its certificate installed. Until then the two URL modules are enabled but idle — their card shows Paused / 已暂停 and offers a shortcut to turn deep inspection on. They still count in the total above; they simply cannot match anything yet. Deep inspection and the certificate covers the setup.
Turning a module off
Each module has its own switch, and turning one off takes effect immediately: the
domains it covers stop being blocked, so ads and trackers from that list can load
again straight away. Because that is a real change to your protection, ClearDeck
asks first. The dialog is titled, for example, Turn off "Ad blocking"?, and its
body spells out that this list’s domains will no longer be blocked.
For the domain modules the app also states the scope plainly:
Blocks this list's domains for every app. There is no per-app exception inside
a bundled module.
My block & allow
My block & allow / 我的拦截与放行 is a card of its own, separate from the five bundles. Two things set it apart:
- You build it yourself from Access log / 访问日志 entries. Open an app, expand its log, and tap Block / 拦截 or Allow / 放行 on a record. You then choose Apply to… / 应用到… — This app only / 仅这个应用 or All apps / 所有应用. The apps guide walks through it.
- It is deliberately not switchable in one tap. The five bundles are one switch away from off; your own rules are not, because they are usually the considered ones.
When it is empty, the card says so:
Nothing here yet. Open an app, expand its access log and tap Block or Allow on a record — what you add shows up here.
Two rules of precedence are worth remembering:
- Your rules outrank the bundled modules. If you have allowed a host, it is allowed even when a module would block it.
- An allow beats a block on the same host. Allow always wins.
Import file
Import file / 导入文件 adds a list you already have on the phone. It accepts
.yaml, .txt and .mrs.
After you pick a file, ClearDeck detects what kind of list it is — Domain list / 域名列表, IP list, Mixed list, or Full URL matching / 完整地址匹配 — and you choose whether it should block or allow. The confirmation dialog shows the type, the action and the entry count before anything is committed, so a file you did not mean to pick is easy to catch. One file can be up to 32 MB; larger ones are refused.
Import link
Import link / 导入链接 turns a URL into a refreshable module. Paste it in,
and the list appears as a new module with its own one-tap Update / 更新 button
and a Last updated: … line, so you can pull a newer copy whenever you want.
One restriction is deliberate: only https:// links are accepted. A rule list
is the firewall rule — a plaintext download could be rewritten in transit by
anyone between you and the server, and the rewritten list would then be enforced
on your phone. HTTPS means the list you receive is the list that was published.
Updates run over HTTPS for the same reason.
A linked module updates only when you ask. It does not poll in the background, so importing a link does not by itself cost you data.
View list and the rule browser
Every module — bundled or imported — has View list / 查看名单. It opens a browser for that list:
- a search box that matches a domain or a path,
- a counter of the form
N of M entries, showing how many entries match what you typed, - and a recently blocked links section, where each blocked request names the
rule behind it with
Matched rule: ….
Where the lists come from
The bundled lists are assembled from well-known public sources: EasyList and EasyList Ad Servers for ads, EasyPrivacy and AdGuard Tracking Protection for trackers, 217heidai/adblockfilters and AWAvenue Ads Rule for both, and Hagezi Threat Intelligence Feeds (TIF, mini) for malicious sites. They are generated offline and committed with the source, so building ClearDeck never touches the network and the lists inside a given version are fixed and reproducible.
Next
- Deep inspection and the certificate — how the two URL modules get switched on
- Adding your own rules — building My block & allow from the access log
This guide is also available in 简体中文