SlipNet includes six anti-censorship protocols. They all get you online, but each hides your traffic in a different way, so if one is detected or blocked you can switch to another. This article explains each one and where SlipNet fits among our other options.
At a glance
Speed and stealth ratings are the ones shown on the SlipNet page in the portal.
| Protocol | Hides traffic as | Speed | Stealth | Devices |
|---|---|---|---|---|
| VayDNS | DNS lookups | Medium | Highest | Android |
| NoizDNS | DNS lookups, with added noise | Medium | Highest | Android |
| DNSTT | DNS lookups | Medium | High | Android |
| Slipstream | DNS lookups (QUIC inside) | Fast | Moderate | Android |
| NaiveProxy | HTTPS web browsing | Fast | High | Android, iOS (Shadowrocket) |
| StunTLS | Encrypted TLS traffic | Medium | High | Android |
On Android, all six work in the free SlipNet app. On iPhone and iPad, only NaiveProxy is available, through Shadowrocket.
VayDNS: recommended in Iran
VayDNS carries your traffic over DNS using the KCP transport, with extra features to avoid DPI detection and to balance traffic across resolvers. It can use several DNS record types. The record type for each VayDNS link is shown next to it on the SlipNet page, so if one stops working you can try a link with a different record type where your server offers one.
Best for: your first try in Iran. Based on recent feedback from users there, it's currently one of the two most reliable protocols. If you use it from Iran, apply the VayDNS settings in Getting Started with SlipNet on Android.
NoizDNS: recommended in Iran
NoizDNS uses the same server side as DNSTT, but the SlipNet app adds random noise to the timing and size of its DNS queries. That makes it harder for filters to spot the tunnel by analysing traffic patterns.
Best for: your first or second try in Iran, and networks that detect DNSTT by its traffic pattern.
DNSTT: the classic DNS tunnel
DNSTT hides your encrypted traffic inside DNS queries and replies, using Curve25519 keys for encryption. To an observer it looks like your device is making ordinary DNS lookups.
Best for: a dependable fallback when VayDNS and NoizDNS don't connect.
Slipstream: the fastest DNS tunnel
Slipstream runs the QUIC protocol (the technology behind HTTP/3) through DNS. QUIC copes well with packet loss and network changes, so Slipstream is usually the quickest of the DNS tunnels. It's also the easiest of them to detect.
Best for: better speed on lightly censored networks, for example for video calls.
NaiveProxy: HTTPS disguise
NaiveProxy doesn't use DNS at all. It runs on a real web server with a genuine TLS certificate on port 443 and makes your traffic look like normal HTTPS browsing from a Chrome browser. Anyone who visits the server directly sees an ordinary website.
Best for: networks where DNS tunnels are blocked but HTTPS still works, and iPhone or iPad users. See Setting Up NaiveProxy on iOS with Shadowrocket.
StunTLS: SSH over TLS
StunTLS wraps an SSH tunnel inside TLS encryption and connects straight to the server's IP address, by default on port 8443. Because it doesn't depend on DNS, it can work where DNS is filtered through local resolvers.
Best for: a quick fallback, and networks such as offices where DNS is tightly controlled.
Where SlipNet fits
DNS tunnels are slower than a normal VPN, so try the faster options first and move down only if they're blocked:
- The PremierVPN app. The main PremierVPN apps now include VLESS (REALITY, xHTTP and CDN) and AmneziaWG. On iPhone and iPad, leave the protocol on Auto and the app tries them in turn. On Windows, use Bypass mode, which tries AmneziaWG, then Cloak, then VLESS. The latest Android and macOS versions add the same protocols as iOS. They're rolling out now. If you don't see these options yet, update the app from Google Play or the Mac download.
- VLESS in a third-party app. Go to Anti-Censorship › VLESS + REALITY and import your Subscription URL into v2rayNG, NekoBox, Sing-Box or V2Box. If our server addresses are blocked, use the CDN-fronted VLESS links on the same page. They're slower but harder to block.
- StormDNS. A DNS-tunnel VPN for heavy censorship, under Anti-Censorship › StormDNS.
- SlipNet. The six protocols above, for when everything else is blocked, under Anti-Censorship › SlipNet.
For a quick decision guide, see Which Protocol Should I Use?