DPI basics

What is deep packet inspection, and how do censors use it against VPNs?

Deep packet inspection (DPI) is network equipment that looks past a packet's address to its contents and patterns. Censors use it to recognise VPN traffic by its fingerprint, to probe suspicious servers, and to throttle or drop connections. Obfuscated protocols respond by making VPN traffic look like ordinary HTTPS or random noise, so it is harder to single out.

DXVPN teamUpdated 5 min read

Key points

  • DPI reads packet patterns, not just addresses and ports.
  • Censors combine passive fingerprinting, active probing and throttling.
  • Encryption hides content but not the shape of a protocol.
  • Obfuscated protocols aim to blend in, not to be invisible.

What deep packet inspection is

Deep packet inspection is the practice of examining the contents and patterns of network traffic, not only its addresses. It is done by specialised equipment placed inside an internet provider's network.

Ordinary routers only read a packet's header: where it comes from, where it goes, and which port it uses. DPI goes further. It reads the first bytes of a connection, notes packet sizes and timing, and compares all of this with a library of known patterns. Businesses use the same technology for traffic management and security. Governments that filter the internet use it to find and block traffic they do not want, including VPNs.

Want to see it from the censor's side? Our interactive "what the censor sees" demo shows the same session through a DPI box's eyes.

What DPI can and cannot see

With a well-encrypted VPN, DPI cannot read what you send. It can still see a lot about the connection itself.

  • Visible: the server's IP address and port, the protocol (TCP or UDP), packet sizes, timing, and the unencrypted parts of a handshake.
  • Often visible: the server name (SNI) in a TLS handshake, and the TLS settings a client offers, which together form a fingerprint.
  • Not visible: the pages you open, the messages you send, or the files you download inside the tunnel.

This is the key point. Encryption protects content, but every protocol has a shape. If that shape is unusual and easy to recognise, a censor does not need to read anything to block it.

Passive fingerprinting

Passive fingerprinting means recognising a protocol from traffic the censor simply watches. It is cheap, fast and works at the scale of a whole country.

Many classic VPN protocols are easy to fingerprint. Plain WireGuard, for example, starts with handshake messages of fixed sizes and known type bytes. A DPI rule can match that in a few packets, which is why DXVPN rates plain WireGuard 1 out of 5 for DPI resistance. OpenVPN has its own well-known patterns too.

Fingerprinting also works on TLS. A TLS handshake lists supported ciphers and extensions in a particular order. Browsers produce familiar lists; unusual software produces unusual ones. A censor can flag connections whose TLS fingerprint does not match any common browser.

Active probing

Active probing is when the censor stops watching and starts asking. It connects to a suspicious server itself and checks how the server answers.

Probing is usually triggered by something passive: a new server with steady encrypted traffic, or an odd handshake. The censor then sends test connections. They might replay a recorded handshake, send random data, or pretend to be a client of a known proxy protocol. If the server replies like a proxy, or behaves strangely, its address can be blocked.

China's Great Firewall is widely documented as using active probing. That is why protocols with a believable cover story matter there.

Throttling and other soft blocking

Not every response is a hard block. Some censors slow traffic down until a VPN is unusable, which is harder to prove and cheaper to undo.

Common soft tactics include:

  • Throttling connections the DPI cannot classify, or all traffic to certain regions.
  • Resetting long-lived connections after a few minutes, so a VPN "connects, then drops".
  • Degrading UDP or TCP on specific networks, such as mobile carriers.
  • Blocking by IP address once a server is identified, regardless of protocol.

Filtering also changes over time. In some countries it tightens around elections, protests or other events, and relaxes afterwards.

How obfuscated protocols respond

Obfuscated protocols do not try to be invisible. They try to look like something a censor cannot afford to block, or like nothing recognisable at all.

StrategyProtocolHow it works
Look like a real websiteVLESS + RealityPresents a real site's TLS 1.3 fingerprint and certificate; hard to tell apart from ordinary HTTPS.
Answer probes with a decoyTrojanA wrong password is passed to a real web server, so probing sees an ordinary website.
Remove the signatureAmneziaWGAdds junk packets and randomises header bytes so the standard WireGuard pattern is gone.
Look like random bytesShadowsocks 2022AEAD-only encryption with no SNI and no TLS handshake. Some censors flag fully random-looking traffic, so this is a fallback.
Use a different transportHysteria2QUIC over UDP with TLS 1.3 inside; useful when TCP is throttled.
Hide behind shared infrastructureVLESS + WebSocketCan run behind a CDN, so blocking it by address means blocking CDN addresses that many other sites share.

Each approach answers a different tactic. Reality and Trojan answer probing. AmneziaWG answers passive fingerprinting. A CDN answers IP blocking. Random-looking traffic avoids known signatures, but research on China's Great Firewall shows that fully encrypted traffic can itself be flagged. That is why a single protocol is rarely enough. For the full breakdown, read VLESS + Reality explained and AmneziaWG vs WireGuard.

How DXVPN deals with DPI

DXVPN is built for networks with DPI-based censorship. Instead of one protocol, every device gets a bundle of configs so the client can fall back when one is blocked.

Your subscription link includes all the protocols on your plan and refreshes every 6 hours. You can manage everything from the web dashboard or from the Telegram bot @dxvpnbot, which helps where websites and app stores are blocked. Two nodes are online, including one in the Netherlands. Nodes in Hong Kong, Tokyo and Singapore are planned. You can check them on the status page.

To choose where to start, see how to choose a VPN protocol, or browse all 7 protocols on the home page.

Questions

Can DPI see what I do inside a VPN?

Not if the tunnel is properly encrypted. DPI can see that a connection exists, where it goes, how big the packets are and when they are sent, but not the content inside the encryption.

How does DPI detect a VPN if the traffic is encrypted?

It looks for patterns that each protocol leaves, such as fixed handshake sizes, known header bytes or unusual TLS settings. It can also connect to a suspicious server itself and see how it responds.

What is active probing?

Active probing is when the censor sends its own test connections to a server it suspects is a proxy. If the server answers like a VPN, it can be blocked; protocols like Trojan and Reality answer like a normal website instead.

Why is my VPN slow but not blocked?

Some networks throttle traffic they cannot classify instead of blocking it. Switching to a protocol that looks like ordinary HTTPS, or to Hysteria2 over UDP, can help.

Sources

  1. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3
  2. RFC 9000: QUIC, a UDP-based multiplexed and secure transport
  3. XTLS/REALITY on GitHub
  4. WireGuard protocol overview
  5. GFW Report: How the Great Firewall of China detects and blocks fully encrypted traffic (USENIX Security 2023)

General information, not legal advice. VPN rules differ by country — check the law where you are.

See it for yourself

Run the “what the censor sees” check on the home page, or start on the free plan — no card needed.

Read next