What is VLESS Reality and how it gets past DPI
How VLESS with Reality disguises itself as an ordinary TLS connection to a real website, and why it is so hard to tell apart from HTTPS.
October 1, 2026 · 3 min readVLESS is a lightweight proxy protocol from the Xray project. On its own it does very little: it carries a user ID and the destination address and leaves encryption to the transport. Reality is a transport built by the XTLS team specifically for networks that use deep packet inspection (DPI).
The problem Reality solves
The classic way to hide a proxy is to wrap it in TLS with its own domain and certificate. That approach has weak points:
- the domain and certificate must be registered somewhere and can be blocked by name;
- if the censor connects to the server itself (active probing), the server may give itself away with an unusual response;
- the TLS fingerprint of a proxy client (cipher suites, extensions) often differs from a browser's.
How Reality works
- Someone else's site as a mask. The server configuration names a real, popular website. The client starts a TLS 1.3 handshake as if connecting to it: the SNI field carries that site's name.
- A browser fingerprint. The client uses the uTLS library and reproduces the TLS fingerprint of Chrome or Firefox.
- Secret authentication. A value derived from an X25519 key exchange with the server's public key, plus a short ID, is embedded in the handshake. Only a client with the right key can produce it.
- Strangers go to the real site. If someone without the key connects, such as a censor's scanner, the server simply proxies them to the real website. The prober sees a genuine certificate and a genuine page.
As a result the server has no certificate of its own that could be blocked, and from the outside the connection is indistinguishable from a visit to a popular site.
XTLS Vision
Inside a VPN connection, most of your traffic is TLS too (HTTPS sites). "TLS inside TLS" leaves a telltale pattern of packet sizes. Vision mode recognises the inner TLS and passes its data through without encrypting it twice, smoothing out packet sizes. This reduces both visibility and CPU load.
Limitations
- Reality runs over TCP, so on lossy networks it is slower than QUIC-based protocols like Hysteria2.
- The choice of mask site matters: it must support TLS 1.3 and be reachable from the server's network.
- No protocol is guaranteed to work forever: filtering systems evolve too, which is why fallbacks matter.
How Colitu sets it up
On every Colitu server VLESS Reality runs on a TCP port, and a VLESS XHTTP variant runs over the same Reality layer for networks that cut long TCP connections. The app picks Reality on networks with DPI and switches to Hysteria2, Trojan or Shadowsocks 2022 automatically if Reality cannot connect. Server addresses and keys are never published: the app receives them over an encrypted channel after you sign in.
More on the security page.