VolnaLink VPN

What DPI is in plain terms

DPI — deep packet inspection. A technology people recall when a VPN suddenly stops connecting. Let's break down what it actually does.

The short answer

Ordinary filtering looks at the recipient's address: where a packet is going. DPI looks at the content and structure: what the connection looks like. That's why it can tell browser HTTPS from a VPN tunnel, even if both are encrypted and go to the same port.

A postal analogy

Imagine mail sorting. Simple filtering is a glance at the address on the envelope: we don't send to this city. DPI is when they look at the envelope itself: its format, its thickness, how it's sealed, what's printed on the flap. The letter isn't opened, but from the external signs they conclude what's inside, and on that basis let it through or not.

What DPI sees in encrypted traffic

The content — it doesn't see; the encryption works. But it sees enough:

  • The start of the connection. The first packets of the TLS handshake are sent in the open: which protocol version, which algorithms the client offers, in what order. Browsers have one such set, VPN clients another.
  • The site name. In ordinary TLS the domain is sent in plain text in the SNI field during the handshake.
  • The sizes and rhythm of packets. A video stream, a page load, and a VPN tunnel produce different characteristic patterns, even if the content is unreadable.
  • Duration and volume. A persistent connection with a steady stream looks different from a series of short requests to a website.

What DPI doesn't see

  • The content of encrypted data: texts, passwords, files.
  • What exactly you do inside an established tunnel.
  • The content of pages opened over HTTPS.

This matters: DPI is a tool for classifying connections, not for reading correspondence.

Test it on your own device

8 hours free, no card required. Full access to all servers.

Why changing the port doesn't help

A common piece of advice is «run the VPN on port 443». Against port-based filtering this works; against DPI it doesn't: it looks not at the port number but at what the handshake looks like. A VPN tunnel on 443 will remain a VPN tunnel on 443.

How protocols respond to DPI

  • Disguise as HTTPS (Trojan): the tunnel mimics the structure of an ordinary web connection, and when requested without a password the server behaves like a web server.
  • Substituting the handshake target (VLESS Reality): the connection looks like a request to a real third-party site, and when probed the server returns that site's genuine response.
  • Changing the transport (Hysteria 2 over QUIC): a different traffic profile and better resilience to packet loss.

Why this isn't solved once and for all

DPI systems update their rules, protocols update their disguise methods. This isn't a problem with a final answer but a process. That's why we don't promise that a specific protocol will work always and everywhere: anyone who promises that is speaking about something they can't know.

What a user should do

In practice — nothing complicated. If the connection won't establish, change the location in the app: this resolves most cases. The client selects the protocol for the network itself.

Ready to connect?

Try VolnaLink VPN free for 8 hours without a card, or pick a plan right away.

FAQ

No. The content of encrypted connections remains unreadable. DPI analyzes the structure of the connection and the open parts of the handshake, not the data inside.
Ordinary blocking looks at the recipient's address — where the traffic is going. DPI looks at what the connection itself looks like, and can tell a VPN from browser HTTPS.
Against port-based filtering — yes, against DPI — no. It analyzes the nature of the handshake, not the port number.
Those for which disguise is part of the design: VLESS Reality, Trojan, Hysteria 2. WireGuard and OpenVPN are recognized by characteristic signatures.
No. Filtering rules and disguise methods are updated on both sides, so no one gives future guarantees here.