Protocol guide

Trojan vs VLESS + Reality: how they differ and when to use each

Both Trojan and VLESS + Reality hide VPN traffic inside TLS so it looks like HTTPS. Classic Trojan needs its own domain and certificate and shows a decoy website to anyone without the password. Reality borrows the handshake and certificate of a real, popular site instead. Pick Reality first on heavily filtered networks and keep Trojan as a close fallback.

DXVPN teamUpdated 5 min read

Key points

  • Both protocols wrap traffic in TLS and answer strangers with a real-looking website.
  • Classic Trojan needs a domain and a valid certificate; Reality borrows a real site's identity.
  • DXVPN rates VLESS + Reality 5/5 and Trojan 4/5 for DPI resistance.
  • Keep both in your app: if one stops working, switch to the other.

The short answer

Trojan and VLESS + Reality solve the same problem in two different ways. Both make a VPN connection look like an ordinary HTTPS visit. They differ in whose identity the server shows to the outside world.

Classic Trojan runs a real TLS server with its own domain and certificate. Reality has no certificate of its own. It presents the handshake and certificate of an existing, popular website. That one difference drives most of the trade-offs below. DXVPN offers both among its up to 7 protocols (availability can vary by server), and your subscription link carries both on the Free, Basic, Pro and Family plans.

How Trojan hides as HTTPS

Trojan behaves like a normal HTTPS web server, because that is what it is on the outside. The VPN part only starts once the client proves it knows the password.

  1. A standard TLS handshake. The client connects, usually on port 443, and completes TLS with the server's own certificate for its own domain.
  2. A password inside the tunnel. The first data the client sends is a hash of its password followed by the address it wants to reach. An observer cannot see this, because it is already encrypted.
  3. Right password: tunnel. If the hash matches, the server forwards the traffic as a proxy.
  4. Wrong password: website. If it does not match, the server passes the connection to a real web server behind it, often called the decoy or fallback. The visitor sees an ordinary site.

The design idea is simple: do not invent a new traffic pattern, just use the most common one on the internet. The Trojan protocol page describes the format in a few lines.

How VLESS + Reality hides as HTTPS

Reality goes one step further and removes the server's own certificate from the picture. The client puts the name of a real, well-known website in the handshake. The server answers with that site's actual certificate.

A secret key, carried in your config, is checked during the handshake. Connections with the key get the VLESS tunnel. Connections without it are forwarded to the real website, so the visitor sees that site and its genuine certificate. The client also uses a browser-like TLS fingerprint, so the handshake resembles a normal browser visit. We explain each step in VLESS + Reality explained.

How each one handles active probing

Some censors do more than watch. They connect to a suspicious server themselves and see how it responds. This is called active probing, and both protocols were built with it in mind.

  • Trojan answers a probe with its decoy website. That works well as long as the decoy looks like a believable site that fits the domain and certificate.
  • Reality answers a probe with the real website it imitates. The prober gets the genuine page and the genuine certificate, so there is less to compare against.

In both cases a probe that does not know the secret sees a website, not a VPN. The difference is in the details a determined censor might check. With Trojan, the domain, its age, its certificate and the decoy's content are all things the operator has to get right. With Reality, most of those details belong to a real site that already has a normal history. For a wider view of these techniques, read what deep packet inspection is.

Certificates and domains

This is the most practical difference for anyone who runs a server. For you as a DXVPN user, the provider handles it and your subscription link carries the settings.

  • Classic Trojan needs a domain name that points to the server and a valid TLS certificate for it. The certificate must be renewed, and the domain itself can draw attention if it is new or obscure.
  • Reality needs no domain or certificate of its own. The operator chooses a suitable real website to imitate, and the Reality documentation gives guidance on which sites work well.
  • Trojan over Reality is also possible. DXVPN lists Trojan with TLS or Reality, so Trojan can borrow a real site's identity too.

Side-by-side comparison

The table sums up the main points. DPI resistance is DXVPN's own 1 to 5 rating, not a guarantee.

Trojan (TLS)VLESS + Reality
What an observer seesTLS to the server's own domainTLS 1.3 to a real, popular website
CertificateThe server's own, for its domainThe real website's certificate
Answer to a probe without the secretA decoy websiteThe real website
Needs own domainYesNo
DPI resistance (DXVPN rating)4/55/5
TransportTCPTCP
DXVPN enginesing-boxsing-box

When to use which

Start with VLESS + Reality where filtering is heaviest. Keep Trojan as your first or second fallback. The two often fail for different reasons, so having both ready is more useful than picking a winner.

  • Heavy DPI and active probing. DXVPN's DPI page recommends VLESS + Reality first for Russia, China, Iran and Turkey, with Trojan among the next options in each.
  • Reality stops working on a network. Switch to Trojan. A rule that catches one disguise does not always catch the other.
  • Older apps. Trojan has been around longer, so some older clients support it but not Reality. Updating the app is usually the better fix.
  • Both fail. Try Shadowsocks 2022, another node, or VLESS + WebSocket. The blocked VPN checklist walks through the order.

Using both with DXVPN

You do not have to set up either protocol by hand. Create an account on the sign-up page or through the Telegram bot @dxvpnbot, then install a compatible app from the download page, such as sing-box, Streisand, v2rayNG, Hiddify or Clash Verge.

Import your subscription link and you will see entries for both protocols along with the rest of your plan. The link refreshes every 6 hours, so server changes reach your app without a new setup. Every plan includes VLESS and Trojan: Free, Pro and Family carry up to 7 protocols, and Basic carries VLESS, Trojan and Shadowsocks. Availability can vary by server; the status page lists the nodes that are online. See the pricing section for details.

Questions

Is Trojan safer than VLESS + Reality?

Both carry your traffic inside TLS, so the content is encrypted either way. The main difference is how well each one blends in with ordinary HTTPS. DXVPN rates VLESS + Reality slightly higher for DPI resistance, 5 out of 5 against 4 out of 5 for Trojan.

Do I need my own domain to use Trojan with DXVPN?

No. Running a Trojan server is the provider's job. Your subscription link already contains the server address, password and TLS settings, so you only import it into a compatible app.

Can Trojan run with Reality?

Yes. DXVPN lists Trojan with TLS or Reality. With Reality the Trojan server borrows a real site's handshake and certificate, much as VLESS + Reality does, instead of using its own certificate.

Which one should I try first in China?

DXVPN's DPI page recommends VLESS + Reality first for China, where active probing is common, followed by Trojan and Shadowsocks 2022. No protocol is guaranteed to work on every network, so keep all three ready.

Sources

  1. Trojan documentation: protocol
  2. trojan-gfw/trojan on GitHub
  3. XTLS/REALITY on GitHub
  4. sing-box documentation: Trojan inbound
  5. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3

General information, not legal advice. VPN rules differ by country — check the law where you are.

See it for yourself

Run the “what the censor sees” check on the home page, or start on the free plan — no card needed.

Read next