Home / Censorship-Resistant Hosting / VLESS + REALITY Hosting
The 2026 gold standard

VLESS + REALITY Hosting

REALITY is the protocol that finally beat active probing: it hijacks a real website's TLS 1.3 handshake, so when the Great Firewall pokes your server it sees an ordinary HTTPS site — no certificate to buy, no domain to burn, no fingerprint to catch. Run it on a fresh offshore IP with the 3x-ui panel, paid in crypto.

No KYC
Crypto Only
No Logs
Fresh, un-blacklisted IP
Full Root
Unlimited bandwidth
Circumvention infrastructure

Why REALITY changed the game

For years the cat-and-mouse was about hiding proxy traffic inside TLS — but censors learned to actively probe suspicious servers and catch the fakes. REALITY inverts the trick: instead of presenting its own certificate, your server relays the genuine TLS handshake of a real, popular website (Microsoft, Apple, a CDN). To a probe, your endpoint is indistinguishable from that site — same certificate, same fingerprint — because for the handshake, it literally is. There's no self-signed cert to flag, no domain of your own to get blocklisted, and nothing for a fingerprint scanner to latch onto. That's why REALITY is the default recommendation for China in 2026.

01

Beats active probing

The GFW pokes suspect servers to unmask proxies. Probe a REALITY endpoint and it answers as the real site it borrows — nothing to unmask.

02

No domain, no cert

Other TLS tricks need a domain and a certificate that can be blocklisted. REALITY needs neither — just your fresh IP and a public SNI to borrow.

03

3x-ui panel included

Manage inbounds, users and share links from a clean web panel. Add a user, copy the QR, done — no hand-edited JSON to get wrong.

04

Featherweight

Xray-core sips ~50 MB of RAM. A VPS-S runs a REALITY endpoint for you and a few devices with capacity to spare.

Characteristics

Protocol characteristics — VLESS + REALITY

What the protocol actually is, how it hides, and where it's strongest — described honestly. No proxy is magic; the right one for your network is.

Server software Xray-core + 3x-ui panel
Transport & camouflage REALITY — borrows a real site’s TLS 1.3 handshake
DPI resistance Highest — no fingerprint, no cert, no domain
Throughput Excellent (TCP + uTLS)
RAM footprint ≈ 50 MB
Setup 3x-ui web panel, ≈ 5 min
Port(s) 443 TCP
Strongest in China, Iran, Russia — 2026 gold standard
Matched VPS

Recommended servers

A proxy is a tiny process — it needs a clean IP and steady bandwidth, not a big machine. Every plan is unmetered NVMe VPS with full root, rented with a token and paid in crypto.

Just me

VPS-S · VPS

  • 2 vCPU · 4 GB DDR4
  • 60 GB NVMe · 1 Gbps
  • Fresh, un-blacklisted IP · Unlimited bandwidth

One person, several devices: VPS-S is plenty for a REALITY endpoint. The cheapest way onto the open internet.

From $7.50/mo Order
Family / group

VPS-M · VPS

  • 4 vCPU · 8 GB DDR4
  • 120 GB NVMe · 1 Gbps
  • Fresh, un-blacklisted IP · Unlimited bandwidth

Share with family or a friend group: VPS-M's extra cores handle a dozen concurrent users on 3x-ui without a stutter.

From $12.00/mo Order
Many users / reselling

VPS-L · VPS

  • 6 vCPU · 16 GB DDR4
  • 200 GB NVMe · 1 Gbps
  • Fresh, un-blacklisted IP · Unlimited bandwidth

Selling access or serving a community: VPS-L runs 3x-ui with many inbounds and users, plus a second protocol on the side.

From $17.00/mo Order

VPS-S — price by jurisdiction

For users in Iran, Turkey and the Gulf, Netherlands and Romania give the lowest latency. For Russia, any European location works. China has no nearby PoP in our network, but REALITY's stealth matters more there than raw latency — Netherlands is the usual pick.

LocationCPURAMStorageUplinkPrice
Moldova Budget Offshore 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $7.50/mo Order
Russia Western-Proof 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $7.50/mo Order
Panama No Data Retention 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $8.50/mo Order
Romania Anti-Retention 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $8.50/mo Order
Netherlands Best Peering 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $9.00/mo Order
Iceland Free Speech Haven 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $10.00/mo Order
Switzerland Premium Privacy 2 vCPU 4 GB DDR4 60 GB NVMe 1 Gbps $11.00/mo Order
Deployment

Set up a VLESS+REALITY server in 5 steps

From a blank VPS to a working endpoint. Commands are copy-paste ready for Ubuntu 24.04.

  1. 1

    Order a VPS on a fresh IP

    Pick VPS-S in a jurisdiction close to you — Netherlands or Romania for the Middle East. Pay in crypto, get root in minutes on an IP that isn't on any blocklist.

  2. 2

    Harden & install 3x-ui

    Key-only SSH first, then one command installs the 3x-ui panel that manages Xray for you.

    # key-only SSH, then install the 3x-ui panel
    bash <(curl -Ls https://raw.githubusercontent.com/mhsanaei/3x-ui/master/install.sh)
  3. 3

    Add a REALITY inbound

    In the panel: protocol VLESS, security REALITY, and a camouflage SNI that's reachable from the censored network. The panel handles the key exchange.

    # in the panel: add an inbound → protocol VLESS, security REALITY
    # pick a camouflage SNI that is reachable from the censored network,
    # e.g. www.microsoft.com or a CDN domain — REALITY relays its real cert
  4. 4

    Import the share link

    The panel prints a vless://…#REALITY link and QR. Import into v2rayN (Windows), v2rayNG (Android), Streisand/FoXray (iOS) or sing-box. No client certificate to leak.

    # the panel prints a vless://...#REALITY share link + QR.
    # import it into v2rayN (Win), v2rayNG (Android), Streisand / FoXray (iOS),
    # or sing-box (any). No client cert, no config file to leak.
  5. 5

    Verify it looks like HTTPS

    From outside, the endpoint answers a normal TLS handshake for your borrowed SNI. To any scanner it's just another HTTPS host.

    # verify from outside: the endpoint answers a normal TLS handshake
    curl -sI https://YOUR_IP --resolve YOUR_SNI:443:YOUR_IP | head -1

REALITY vs the old TLS tricks (Trojan, VMess+TLS)

Trojan and VMess-over-TLS both wrap proxy traffic in a legitimate-looking TLS session — but they present a certificate for a domain you control, and that domain (and its cert) can be probed, fingerprinted and blocklisted. REALITY removes the weak link: there is no domain of yours and no certificate of yours. Your server completes the handshake using a real third-party site's certificate, then quietly switches to carrying your traffic only for authenticated clients. A censor that probes sees the real site; a scanner that fingerprints sees the real site's TLS stack. There's simply nothing that says 'proxy'.

Choosing a camouflage SNI

REALITY borrows the TLS handshake of a real 'dest' site you point it at. Pick one that is (1) reachable and unblocked from inside the censored network, (2) served over TLS 1.3 with the modern X25519 curve, and (3) plausible as a destination — a big CDN, a Microsoft or Apple endpoint, a popular site that isn't itself blocked. Avoid anything the censor has an interest in blocking, and avoid tiny or region-locked sites. The 3x-ui panel can test a candidate SNI for compatibility before you commit.

Running it from the 3x-ui panel

3x-ui turns Xray into a point-and-click job: create inbounds, add users with traffic quotas and expiry dates, and hand out per-user share links or QR codes. It's ideal if you're serving a family or reselling — each person gets their own credential you can revoke without touching anyone else. Put the panel itself behind a non-standard port and key-only SSH, and never expose it to the open internet without a password. Our first-hour hardening checklist covers the basics.

When REALITY isn't the answer

REALITY is superb against DPI and active probing, but it rides on TCP — so on a deliberately throttled or extremely lossy mobile network (common in Iran during unrest) a UDP/QUIC protocol like Hysteria2 can feel dramatically faster. And if your goal is purely Telegram, a MTProto proxy is lighter and purpose-built. The good news: full root means you can run REALITY and a fallback on the same VPS, different ports, and switch when the network changes.

FAQ

VLESS + REALITY hosting FAQ

01 What does a REALITY server cost?

A VPS-S from $7.50/mo (Moldova/Russia) to $11/mo (Switzerland) runs a REALITY endpoint for you with room for several devices. Unlimited bandwidth is included — there's no traffic meter to watch.

02 Do I need my own domain?

No — that's a key advantage. REALITY borrows a public third-party site's TLS handshake, so you need neither a domain nor a certificate. Just the VPS's IP and a camouflage SNI to point at.

03 Does it really beat the Great Firewall's active probing?

REALITY is specifically designed for it: a probe to your endpoint gets the genuine response of the real site you borrow, so there's nothing to unmask. It's the most probe-resistant approach available in 2026. No method is guaranteed forever, which is why you can rotate IPs freely.

04 Which client apps support it?

All the major ones: v2rayN and NekoBox on Windows, v2rayNG on Android, Streisand/FoXray/Shadowrocket on iOS, and sing-box everywhere. The 3x-ui panel gives you a share link and QR that these import directly.

05 Can one server run REALITY for several people?

Yes — 3x-ui manages multiple users on one inbound, each with their own link, quota and expiry. A VPS-S handles a handful; step up to VPS-M or VPS-L as concurrent users grow.

06 What if the borrowed SNI stops working?

Just pick a different camouflage site in the panel and re-issue the links — a two-minute change. Keeping two known-good SNIs in mind is a good habit for when networks shift.

Deploy an undetectable proxy

Xray + REALITY on a fresh offshore IP, managed from 3x-ui, paid in crypto with no identity. From $7.50/mo, live in minutes.

View recommended VPS All protocols