DPI — deep packet inspection. A technology people recall when a VPN suddenly stops connecting. Let's break down what it actually does.
The short answer
Ordinary filtering looks at the recipient's address: where a packet is going. DPI looks at the content and structure: what the connection looks like. That's why it can tell browser HTTPS from a VPN tunnel, even if both are encrypted and go to the same port.
A postal analogy
Imagine mail sorting. Simple filtering is a glance at the address on the envelope: we don't send to this city. DPI is when they look at the envelope itself: its format, its thickness, how it's sealed, what's printed on the flap. The letter isn't opened, but from the external signs they conclude what's inside, and on that basis let it through or not.
What DPI sees in encrypted traffic
The content — it doesn't see; the encryption works. But it sees enough:
- The start of the connection. The first packets of the TLS handshake are sent in the open: which protocol version, which algorithms the client offers, in what order. Browsers have one such set, VPN clients another.
- The site name. In ordinary TLS the domain is sent in plain text in the SNI field during the handshake.
- The sizes and rhythm of packets. A video stream, a page load, and a VPN tunnel produce different characteristic patterns, even if the content is unreadable.
- Duration and volume. A persistent connection with a steady stream looks different from a series of short requests to a website.
What DPI doesn't see
- The content of encrypted data: texts, passwords, files.
- What exactly you do inside an established tunnel.
- The content of pages opened over HTTPS.
This matters: DPI is a tool for classifying connections, not for reading correspondence.
Test it on your own device
8 hours free, no card required. Full access to all servers.
Why changing the port doesn't help
A common piece of advice is «run the VPN on port 443». Against port-based filtering this works; against DPI it doesn't: it looks not at the port number but at what the handshake looks like. A VPN tunnel on 443 will remain a VPN tunnel on 443.
How protocols respond to DPI
- Disguise as HTTPS (Trojan): the tunnel mimics the structure of an ordinary web connection, and when requested without a password the server behaves like a web server.
- Substituting the handshake target (VLESS Reality): the connection looks like a request to a real third-party site, and when probed the server returns that site's genuine response.
- Changing the transport (Hysteria 2 over QUIC): a different traffic profile and better resilience to packet loss.
Why this isn't solved once and for all
DPI systems update their rules, protocols update their disguise methods. This isn't a problem with a final answer but a process. That's why we don't promise that a specific protocol will work always and everywhere: anyone who promises that is speaking about something they can't know.
What a user should do
In practice — nothing complicated. If the connection won't establish, change the location in the app: this resolves most cases. The client selects the protocol for the network itself.