VLESS is a tunnel protocol from the Xray project that carries your traffic with almost no overhead and leaves encryption to the TLS layer underneath, so the connection looks exactly like a browser talking to a website over HTTPS.
Reality is an extension that goes one step further: the server borrows the identity of a real, well-known website during the TLS handshake, so anyone inspecting the connection sees a legitimate visit to that site. Together they're the current answer to networks that recognize and block conventional VPN protocols.
VLESS WireGuard looks like HTTPS ✓ ✗ passes DPI ✓ ✗ raw speed ▇▇▇ ▇▇▇▇ simple config ▇▇ ▇▇▇▇ works over TCP ✓ ✗
The problem VLESS solves: VPNs that get recognized
WireGuard, OpenVPN and IKEv2 are all secure, but their traffic has a shape. A firewall that inspects your packets can tell "this is a WireGuard handshake" or "this is OpenVPN" and drop or throttle it. So that's what's happening to you on some corporate and campus networks, in hotels with aggressive filtering, and in countries that restrict VPNs. The comparison of conventional protocols is in WireGuard vs OpenVPN; the short version is that none of them was designed to hide.
VLESS was. Its design goal isn't speed or simplicity, though it has both, but indistinguishability from ordinary web traffic.
a tunnel has to look like something ├─ like a VPN → easy to classify └─ like a site → hard to classify VLESS with Reality picks the second
How VLESS works
Conventional protocols wrap each packet in their own header format, and that format is what a firewall recognizes. VLESS adds a minimal header, a few bytes with a user ID, and hands the data to a transport layer. With TLS as the transport, the connection uses port 443, a normal TLS handshake, and a normal encrypted stream. From the outside it's an HTTPS session.
VLESS itself doesn't encrypt. This is deliberate: TLS already does, and encrypting twice would add cost without benefit. What you get is throughput close to WireGuard's, with a completely different traffic profile.
transport how packets travel masking what it looks like addressing which key is whose └─ encryption is borrowed from TLS; VLESS invents no cryptography
What is Reality in VLESS?
TLS-based tunnels had one remaining weak point: the server needed its own certificate and domain name, and a careful observer could ask whether that domain was a real website or a VPN endpoint. Reality removes the question. During the handshake, the VLESS server presents the TLS identity of a real, popular website; the handshake is cryptographically verified against that site's actual certificate. A client with the right key completes the tunnel; anyone else, including a probe from a firewall, is transparently forwarded to the real website and sees nothing unusual.
So the server needs no domain and no certificate of its own, nobody can identify it by poking at it, and your traffic is a valid TLS (the padlock in your address bar) session with a site nobody would think twice about. This is why "VLESS + Reality" is the combination most often recommended for hostile networks.
ordinary TLS your domain, your cert
└─ a domain can be listed
Reality borrows a real site's
handshake
└─ looks like traffic
to that siteVLESS speed and battery vs WireGuard
Because VLESS does little work of its own and relies on TLS 1.3, it's close to WireGuard in throughput and battery use, and well ahead of OpenVPN. What actually decides your speed is the same as with any protocol: how far the server is and how busy it is. Why speed changes with a VPN at all is in does a VPN slow down your internet.
VLESS itself no cryptography
of its own
the transport standard TLS
Reality a real site's
handshake
└─ this is a feature: no new
cryptography to get wrongIs VLESS secure?
Encryption comes from TLS 1.3, the same as any modern website, with the server authenticated through Reality's handshake. The protocol has been in wide use since 2023 and is open source. As with any tunnel, how safe you actually are comes down to how your client is set up: DNS must go through the tunnel, IPv6 must be handled, and a kill switch should cover reconnects. The checks in is my DNS leaking apply exactly the same way.
the VLESS protocol itself the Reality mode the XTLS-Vision flow, if used └─ an old core silently fails on a key that uses a newer one
VLESS subscription links and clients
You'll usually get VLESS servers as a subscription link: one URL holding a list of servers, which your client fetches and keeps up to date. The flow:
- Install a client. iPhone: Streisand, V2Box, Hiddify, Shadowrocket. Android: v2rayNG, Hiddify. Windows and macOS: Hiddify, v2rayN, Clash-based clients. Or the provider's own app, which handles all of this.
- Copy the subscription link from your account.
- In the client, add a subscription and paste the link; the server list appears.
- Pick a server and connect; the operating system asks once to add a VPN configuration.
- Open What Is My IP and confirm the server's address.
If your client offers a TUN or "system-wide" mode, turn it on. That's what makes the whole thing behave like a VPN for every app instead of just your browser.
vless:// id@host:port
?security=reality
&sni=front domain
&pbk=public key
└─ not a password: the entire
configuration on one lineIf you have a link and the parameters mean nothing, take it apart without revealing the identifier.
Explain the parameters in my VLESS link.
It looks like this, with the id and host removed:
vless://XXX@XXX:443?security=(yours)
&type=(yours)&sni=(yours)
&fp=(yours)&flow=(yours)
Say what each parameter means, which mode I am
running, and which kinds of network this setup
usually passes and which it does not.
Do not invent parameters my link does not have.
VLESS or WireGuard?
- Ordinary home, office and mobile networks: WireGuard is a little faster and lighter.
- Networks that block or throttle VPNs, travel to restricted countries, hotels and campuses with filtering: VLESS with Reality.
- Not sure: an app that switches automatically will pick WireGuard where it works and VLESS where it doesn't.
The two cover each other, which is why serious clients ship both instead of picking a side. Honestly, on a normal home connection you won't feel the difference between them. The day you will is the day you're on a network that doesn't want you tunneling at all, and that's the day VLESS earns its keep.
404 VPN provides VLESS with Reality in its Android and macOS apps and, since September 2026, WireGuard configs for Istanbul and Marseille from the dashboard; you choose the protocol yourself, and on networks that block WireGuard, VLESS is the one to use. Both keep DNS inside the tunnel, and the Android app blocks traffic during reconnects with a kill switch. The connection is described on the how it works page; get started here.