VPS-S · VPS
- 2 vCPU · 4 GB DDR4
- 60 GB NVMe · 1 Gbps
- Fresh, un-blacklisted IP · Unlimited bandwidth
Just you and a few friends: VPS-S runs mtg with capacity to spare — the cheapest way to keep Telegram alive.
When Telegram gets blocked — as it regularly is in Iran and Russia — an MTProto proxy brings it back with a single tap. It's Telegram's own proxy protocol, purpose-built and featherweight, and with fake-TLS it looks like an ordinary HTTPS site. Run your own on a fresh offshore IP, paid in crypto, and share it with anyone who needs Telegram back.
Telegram is a lifeline in censored countries — news, organizing, staying in touch — which is exactly why it's a frequent block target. MTProto is Telegram's native proxy protocol: it only carries Telegram, so it's tiny and fast, and Telegram builds first-class support right into the app (one tap on a tg:// link and you're connected, no separate client). The modern mtg server adds fake-TLS, which dresses the connection as a normal HTTPS session to a real domain, so a DPI box can't easily tell it's a Telegram proxy. Public MTProto proxies exist but are overloaded and quickly blocked; your own private one, on a fresh IP, is fast and yours to share on your terms.
Telegram supports MTProto natively. Open the tg:// link or scan the QR and it's configured — nothing to install, perfect for non-technical friends and family.
mtg's fake-TLS mode dresses the proxy as an HTTPS connection to a real domain, so DPI sees an ordinary TLS session, not a Telegram tunnel.
It only carries Telegram, so it's the lightest server here — ~20 MB of RAM. A VPS-S serves a whole group without effort.
Public proxies are crowded and blocked fast. A private proxy on a fresh IP stays fast and unblocked far longer, and you decide who gets it.
What the protocol actually is, how it hides, and where it's strongest — described honestly. No proxy is magic; the right one for your network is.
| Server software | mtg (9seconds/mtg) or official MTProxy |
|---|---|
| Transport & camouflage | MTProto + fake-TLS (dd / ee secret) |
| DPI resistance | High for Telegram — fake-TLS mimics an HTTPS site |
| Throughput | Excellent — purpose-built for Telegram |
| RAM footprint | ≈ 20 MB |
| Setup | mtg single binary, ≈ 5 min |
| Port(s) | 443 TCP |
| Strongest in | Iran, Russia — Telegram access specifically |
A proxy is a tiny process — it needs a clean IP and steady bandwidth, not a big machine. Every plan is unmetered NVMe VPS with full root, rented with a token and paid in crypto.
Just you and a few friends: VPS-S runs mtg with capacity to spare — the cheapest way to keep Telegram alive.
A larger group or channel audience: VPS-M handles many concurrent Telegram users comfortably.
Serving a big community: VPS-L absorbs hundreds of concurrent connections, still barely using the machine.
For Iranian and Russian users, Netherlands and Romania offer the lowest latency and the freshest IP ranges; Moldova is the cheapest. Keep a second location provisioned so you can hand out a backup link the moment the primary IP is filtered.
| Location | CPU | RAM | Storage | Uplink | Price | |
|---|---|---|---|---|---|---|
| Moldova Budget Offshore | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $7.50/mo | Order |
| Russia Western-Proof | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $7.50/mo | Order |
| Panama No Data Retention | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $8.50/mo | Order |
| Romania Anti-Retention | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $8.50/mo | Order |
| Netherlands Best Peering | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $9.00/mo | Order |
| Iceland Free Speech Haven | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $10.00/mo | Order |
| Switzerland Premium Privacy | 2 vCPU | 4 GB DDR4 | 60 GB NVMe | 1 Gbps | $11.00/mo | Order |
From a blank VPS to a working endpoint. Commands are copy-paste ready for Ubuntu 24.04.
VPS-S is more than enough. Pick a jurisdiction near your users — Netherlands or Romania for Iran. Pay in crypto, get root on a clean IP.
Key-only SSH, then allow TCP 443 in the firewall — using 443 lets the fake-TLS camouflage blend in with normal HTTPS.
Drop in the mtg binary and generate a fake-TLS secret tied to a real domain to imitate (a big, unblocked site).
# mtg — the modern MTProto proxy
curl -L https://github.com/9seconds/mtg/releases/latest/download/mtg-linux-amd64 -o /usr/local/bin/mtg
chmod +x /usr/local/bin/mtg
mtg generate-secret --hex tls-domain www.cloudflare.com
Start mtg on 443 with your secret. That's it — no config file to speak of, one process, negligible resources.
# run it with the fake-TLS secret from the previous step
mtg simple-run -n 1 0.0.0.0:443 SECRET &
mtg prints a tg://proxy?… link and QR. Send it to anyone: they tap it, Telegram sets itself up, and they're back online. No app to install.
# mtg prints a tg://proxy?server=...&port=443&secret=ee... link + QR.
# open it on any phone: Telegram → Settings → Data → Proxy → it just works.
An MTProto proxy is deliberately narrow: it carries Telegram and nothing else. That's a feature, not a limitation — it means dead-simple setup, native in-app support, tiny resource use, and one-tap sharing with people who'd never install a VPN client. If Telegram is the thing that's blocked and the thing you need, MTProto is the fastest, friendliest fix. If you also need to reach blocked websites, news sites or apps, you want a general proxy like VLESS+REALITY or Shadowsocks alongside it. Many people run both on one VPS: MTProto for Telegram, a general protocol for everything else.
Early MTProto proxies had a recognizable handshake that censors learned to spot and block. The modern answer, built into mtg, is fake-TLS (the 'ee'/dd secret): the proxy wraps itself to look like a normal TLS 1.3 connection to a real, popular domain you choose. A DPI box inspecting the traffic sees what appears to be an ordinary HTTPS session to that site, with nothing Telegram-shaped about it. Choose a camouflage domain that's big and unblocked in your target country, set a fresh secret, and the proxy blends into everyday web traffic.
The reason public MTProto proxies die fast is scale and exposure: thousands of people hammer them and censors harvest the widely-posted links. A private proxy shared with a known circle lasts far longer. Keep the link off public channels, hand it out person to person, and if you're running one for a community, rotate the secret and IP periodically. Because you pay with a token, spinning up a fresh proxy on a new IP is a two-minute, no-identity operation whenever one gets tired.
If you're the person keeping a family, newsroom or activist group on Telegram, a little operational habit goes a long way: run mtg under systemd so it survives reboots, keep a second VPS in another jurisdiction ready to go, and pre-share a backup tg:// link so people can switch instantly if the first IP is blocked. The server load is trivial — MTProto is so light that a single VPS-S can hold a surprisingly large group — so the real work is just IP hygiene and having a spare. Our hardening checklist covers locking the box down.
An MTProto proxy only carries Telegram, and Telegram supports it natively — one tap on a link, no app to install, almost no server load. A VPN routes everything but needs a client and more setup. For 'just get Telegram back', MTProto is simpler and faster; for reaching other blocked sites too, add a general proxy.
Yes — that's the beauty of it. You send them a tg:// link or QR; they tap it and Telegram configures itself. No account, no app, no settings to explain. It's the friendliest circumvention tool to hand to family.
Fake-TLS makes the proxy look like a normal HTTPS connection to a real domain, which defeats the simple fingerprinting that blocked older MTProto proxies. No method is permanent, but a private fake-TLS proxy on a fresh IP stays unblocked far longer than a public one — and you can rotate in minutes.
MTProto is so light that a VPS-S handles a large group; VPS-M or VPS-L covers a channel-sized audience or a whole community. Unlimited bandwidth means heavy Telegram media use won't hit a cap.
From $7.50/mo for a VPS-S — the cheapest tier is overkill for MTProto's tiny footprint. No card needed; pay with a token in USDT, XMR or six other coins.
Deploy mtg on a fresh VPS in another jurisdiction (minutes, no ID) and share the new tg:// link. Keeping a spare proxy pre-provisioned means your group is never offline for more than the time it takes to paste a link.
Related reading: Self-Hosted VPN on a No-KYC VPS: WireGuard vs OpenVPN · The First Hour of VPS Hardening: A Checklist · Self-hosted VPN use case
Your own MTProto proxy on a fresh offshore IP, fake-TLS camouflaged, paid in crypto. From $7.50/mo — share it and reconnect.