By Eric L.
09/08/2026 · 7 MIN READ

VLESS is a tunnel protocol from the Xray project that carries your traffic with almost no overhead and leaves encryption to the TLS layer underneath, so the connection looks exactly like a browser talking to a website over HTTPS.

Reality is an extension that goes one step further: the server borrows the identity of a real, well-known website during the TLS handshake, so anyone inspecting the connection sees a legitimate visit to that site. Together they're the current answer to networks that recognize and block conventional VPN protocols.

VLESS VS WIREGUARDFIG. 01
                  VLESS  WireGuard
looks like HTTPS  ✓      ✗
passes DPI        ✓      ✗
raw speed         ▇▇▇    ▇▇▇▇
simple config     ▇▇     ▇▇▇▇
works over TCP    ✓      ✗
Five checks side by side. WireGuard edges ahead on raw numbers, but the row that decides whether you connect at all is the one it fails.

The problem VLESS solves: VPNs that get recognized

WireGuard, OpenVPN and IKEv2 are all secure, but their traffic has a shape. A firewall that inspects your packets can tell "this is a WireGuard handshake" or "this is OpenVPN" and drop or throttle it. So that's what's happening to you on some corporate and campus networks, in hotels with aggressive filtering, and in countries that restrict VPNs. The comparison of conventional protocols is in WireGuard vs OpenVPN; the short version is that none of them was designed to hide.

VLESS was. Its design goal isn't speed or simplicity, though it has both, but indistinguishability from ordinary web traffic.

THE PROBLEM THEY SOLVEFIG. 02
a tunnel has to look like something
  ├─ like a VPN  → easy to classify
  └─ like a site → hard to classify
VLESS with Reality picks the second

How VLESS works

Conventional protocols wrap each packet in their own header format, and that format is what a firewall recognizes. VLESS adds a minimal header, a few bytes with a user ID, and hands the data to a transport layer. With TLS as the transport, the connection uses port 443, a normal TLS handshake, and a normal encrypted stream. From the outside it's an HTTPS session.

WHAT A FIREWALL SEES ON THE WIREWIREGUARD, OPENVPN, IKEV2Own headera known shapeYour dataRecognizeddropped or throttledVLESS OVER TLSTLS on port 443: handshake, encrypted streamVLESS headerYour dataAn HTTPS sessionnothing VPN-shapedThe VLESS header is a few bytes with a user ID; TLS does the encrypting.
Classic tunnels carry a shape a firewall knows; VLESS hides its few bytes inside an ordinary TLS stream.

VLESS itself doesn't encrypt. This is deliberate: TLS already does, and encrypting twice would add cost without benefit. What you get is throughput close to WireGuard's, with a completely different traffic profile.

WHAT VLESS IS MADE OFFIG. 03
transport   how packets travel
masking     what it looks like
addressing  which key is whose
   └─ encryption is borrowed from TLS;
      VLESS invents no cryptography

What is Reality in VLESS?

TLS-based tunnels had one remaining weak point: the server needed its own certificate and domain name, and a careful observer could ask whether that domain was a real website or a VPN endpoint. Reality removes the question. During the handshake, the VLESS server presents the TLS identity of a real, popular website; the handshake is cryptographically verified against that site's actual certificate. A client with the right key completes the tunnel; anyone else, including a probe from a firewall, is transparently forwarded to the real website and sees nothing unusual.

WHO GETS WHAT FROM A REALITY SERVERClient with the keyyour appAnyone elsea firewall probe tooVLESS + Reality servershows a real site’s identityTunnel completesyour traffic flowsThe real websiteprobe sees nothing unusualforwarded, transparently
Only the right key opens the tunnel; a curious probe just gets the real website.

So the server needs no domain and no certificate of its own, nobody can identify it by poking at it, and your traffic is a valid TLS (the padlock in your address bar) session with a site nobody would think twice about. This is why "VLESS + Reality" is the combination most often recommended for hostile networks.

WHAT REALITY ADDSFIG. 04
ordinary TLS   your domain, your cert
               └─ a domain can be listed
Reality        borrows a real site's
               handshake
               └─ looks like traffic
                  to that site

VLESS speed and battery vs WireGuard

Because VLESS does little work of its own and relies on TLS 1.3, it's close to WireGuard in throughput and battery use, and well ahead of OpenVPN. What actually decides your speed is the same as with any protocol: how far the server is and how busy it is. Why speed changes with a VPN at all is in does a VPN slow down your internet.

WHERE THE ENCRYPTION COMES FROMFIG. 05
VLESS itself   no cryptography
               of its own
the transport  standard TLS
Reality        a real site's
               handshake
   └─ this is a feature: no new
      cryptography to get wrong

Is VLESS secure?

Encryption comes from TLS 1.3, the same as any modern website, with the server authenticated through Reality's handshake. The protocol has been in wide use since 2023 and is open source. As with any tunnel, how safe you actually are comes down to how your client is set up: DNS must go through the tunnel, IPv6 must be handled, and a kill switch should cover reconnects. The checks in is my DNS leaking apply exactly the same way.

WHAT A CLIENT NEEDS TO SUPPORTFIG. 06
the VLESS protocol itself
the Reality mode
the XTLS-Vision flow, if used
   └─ an old core silently fails on
      a key that uses a newer one

You'll usually get VLESS servers as a subscription link: one URL holding a list of servers, which your client fetches and keeps up to date. The flow:

  1. Install a client. iPhone: Streisand, V2Box, Hiddify, Shadowrocket. Android: v2rayNG, Hiddify. Windows and macOS: Hiddify, v2rayN, Clash-based clients. Or the provider's own app, which handles all of this.
  2. Copy the subscription link from your account.
  3. In the client, add a subscription and paste the link; the server list appears.
  4. Pick a server and connect; the operating system asks once to add a VPN configuration.
  5. Open What Is My IP and confirm the server's address.

If your client offers a TUN or "system-wide" mode, turn it on. That's what makes the whole thing behave like a VPN for every app instead of just your browser.

THE SUBSCRIPTION LINKFIG. 07
vless://  id@host:port
          ?security=reality
          &sni=front domain
          &pbk=public key
   └─ not a password: the entire
      configuration on one line

If you have a link and the parameters mean nothing, take it apart without revealing the identifier.

Prompt for an AI
Explain the parameters in my VLESS link.

It looks like this, with the id and host removed:

vless://XXX@XXX:443?security=(yours)
&type=(yours)&sni=(yours)
&fp=(yours)&flow=(yours)

Say what each parameter means, which mode I am
running, and which kinds of network this setup
usually passes and which it does not.
Do not invent parameters my link does not have.

VLESS or WireGuard?

  • Ordinary home, office and mobile networks: WireGuard is a little faster and lighter.
  • Networks that block or throttle VPNs, travel to restricted countries, hotels and campuses with filtering: VLESS with Reality.
  • Not sure: an app that switches automatically will pick WireGuard where it works and VLESS where it doesn't.

The two cover each other, which is why serious clients ship both instead of picking a side. Honestly, on a normal home connection you won't feel the difference between them. The day you will is the day you're on a network that doesn't want you tunneling at all, and that's the day VLESS earns its keep.

404 VPN provides VLESS with Reality in its Android and macOS apps and, since September 2026, WireGuard configs for Istanbul and Marseille from the dashboard; you choose the protocol yourself, and on networks that block WireGuard, VLESS is the one to use. Both keep DNS inside the tunnel, and the Android app blocks traffic during reconnects with a kill switch. The connection is described on the how it works page; get started here.