Protocol guide
What is VLESS + Reality, and why is it hard for DPI to block?
VLESS + Reality is a VPN transport that makes your connection look like an ordinary TLS 1.3 visit to a real, popular website. VLESS carries the traffic; Reality presents that website's TLS fingerprint and certificate to anyone watching. Deep packet inspection sees what looks like normal HTTPS, so blocking it by pattern risks blocking the real site too.
Key points
- VLESS is a lightweight proxy protocol; Reality is the disguise layer on top.
- A passive observer sees a TLS 1.3 handshake that matches a real website.
- Probes without the right key get the real website back, not a VPN.
- It is designed to resist DPI, not guaranteed to pass every network.
VLESS + Reality in one paragraph
VLESS + Reality is a way to tunnel your traffic so that, from the outside, it looks like a normal HTTPS visit to a well-known website. It combines two parts: VLESS, which moves your data, and Reality, which handles the disguise.
Most VPN protocols were built for privacy on friendly networks. They encrypt well, but their traffic has a recognisable shape. On networks with deep packet inspection (DPI), that shape is enough to get the connection throttled or dropped. Reality was built for exactly that situation. It is one of DXVPN's 7 protocols, and the one we suggest first where filtering is heaviest. You can compare it with the others on the protocols page.
What VLESS does
VLESS is a lightweight proxy protocol from the V2Ray and Xray family. It identifies your account with a user ID and forwards your traffic to the server, and very little else.
VLESS itself does not add its own encryption layer. That is deliberate: it expects to run inside a secure transport such as TLS, so it avoids encrypting everything twice. This keeps it fast and simple. The trade-off is that VLESS on its own says nothing about how the connection looks on the wire. The transport underneath decides that, and that is where Reality comes in.
VLESS can also run over other transports. DXVPN offers VLESS + WebSocket, which can sit behind a CDN. We cover when to use each one in how to choose a VPN protocol.
What Reality adds
Reality makes the TLS handshake of your VPN connection match the handshake of a real website. The server presents that site's TLS fingerprint and certificate, so a passive observer sees what looks like HTTPS to that site.
Here is the idea, step by step:
- Your client opens a TLS 1.3 connection. The server name (SNI) in the first message is a real, popular website, not a VPN domain.
- The handshake looks like the real thing. The client uses a TLS fingerprint typical of a common browser, and the certificate that comes back belongs to the real website.
- A hidden key decides what happens next. Your client carries a key that only the DXVPN server recognises. If the key checks out, the server treats the session as yours and starts carrying VLESS traffic.
- Everyone else gets the real website. If a connection arrives without the right key, the server forwards it to the genuine site. The visitor sees an ordinary web page.
Older approaches needed you to own a domain and a certificate, and the certificate itself could give the server away. Reality borrows the identity of a site that already exists, so there is no suspicious certificate to spot.
UDP packets with a fixed handshake size and known message-type bytes. A DPI box can match the pattern in a few packets.
A TLS 1.3 connection, typically on port 443, to what looks like a well-known website, with a browser-like fingerprint and that site's real certificate.
You can watch this difference play out in the interactive "what the censor sees" demo on our home page.
Why DPI finds it hard to block
DPI blocks what it can recognise. Reality is designed so that there is little to recognise, and so that a wrong guess costs the censor something real.
A censor has three common tools. Reality is built to answer each one:
- Passive fingerprinting. DPI looks at handshake sizes, TLS extensions and server names. With Reality these match a normal browser talking to a normal site. The traffic is hard to tell apart from ordinary HTTPS.
- Active probing. Some censors connect to a suspicious server themselves to see how it answers. A Reality server without the key in the request simply behaves like the website it imitates.
- Collateral damage. Blocking by pattern could also block visits to the real site whose identity is borrowed. Censors tend to avoid rules that break popular services.
For a wider look at how inspection works, read what deep packet inspection is.
Limits and honest caveats
VLESS + Reality raises the bar for censors, but it is not magic. Knowing its limits helps you react quickly when something changes.
- IP blocking still works. If a censor blocks the server's address, the disguise does not matter. Switching to another node is the fix.
- Behaviour over time can stand out. One long, busy connection to a single site may look unusual on some networks. Censors experiment with this kind of analysis.
- It needs a compatible app. Reality runs in v2ray-, Clash- and sing-box-compatible clients, not in the VPN settings built into your operating system.
- It is TCP-based. Where TCP is throttled but UDP is not, Hysteria2 over QUIC may feel faster.
How DXVPN uses VLESS + Reality
At DXVPN, VLESS + Reality runs on sing-box, an open-source engine, on servers we operate ourselves. Free, Pro and Family plans include all 7 protocols; Basic includes VLESS, Trojan and Shadowsocks.
Our DPI resistance rating for it is 5 out of 5, the highest among our 7 protocols. We list it first for Russia, China, Iran and Turkey. Traffic uses TLS 1.3 with Reality on top. DXVPN does not log the content of your traffic, the sites you visit, or your DNS queries; more on that on the trust section.
You do not need to configure Reality by hand. Your subscription link carries the settings and refreshes every 6 hours. If Reality stops working on your network, your app can fall back to Trojan, Shadowsocks 2022 or another protocol in the same bundle. If that does not help, follow the five-step checklist for a blocked VPN.
How to start using it
Getting VLESS + Reality running takes a few minutes. You need an account, a compatible app and your subscription link.
- Create an account on the website or through the Telegram bot @dxvpnbot. The Free plan needs no card.
- Install a client from the download page, such as sing-box, Streisand, v2rayNG or Hiddify.
- Import your subscription link or scan the QR code. Choose the VLESS + Reality entry and connect.
If you want to see how the full flow fits together, the how it works section walks through it with pictures.
Questions
Is VLESS + Reality the same as a normal VPN?
It does the same job of tunnelling your traffic to a server, but it is built as a proxy transport rather than a classic VPN protocol. It runs in v2ray-, Clash- and sing-box-compatible apps, not in the built-in VPN settings of your phone.
Can VLESS + Reality be blocked?
Yes, any protocol can be blocked by a determined censor, for example by blocking a server's IP address. Reality is designed to make fingerprinting hard, so blocking it by traffic pattern alone is difficult without also hurting real websites.
Which apps support VLESS + Reality?
Recent versions of clients built on sing-box, Xray or Clash Meta cores support it, including sing-box, Streisand, V2Box, Shadowrocket, v2rayNG, NekoBox, Hiddify, V2rayN and Clash Meta based apps. Keep your app up to date.
Is VLESS + Reality slower than other protocols?
It adds little overhead because it uses a single TLS 1.3 layer. On networks without heavy filtering, AmneziaWG is usually faster, but Reality is the stronger choice when DPI is aggressive.
Sources
General information, not legal advice. VPN rules differ by country — check the law where you are.
See it for yourself
Run the “what the censor sees” check on the home page, or start on the free plan — no card needed.