What is the Stealth VPN protocol?

VPNs are useful, but they sometimes get blocked, whether by a school or workplace network admin trying to limit access to restricted content, or by governments like China or Russia censoring the internet. The Stealth VPN protocol is built to get around such blocks by mimicking everyday traffic.

VPNs implement this feature in a variety of ways, so we’ll go over some of the most common ones below. We’ll also include steps to enable it where available, and when it makes sense to use the Stealth protocol over others.

What is the Stealth VPN protocol?

The Stealth VPN protocol is a privacy feature designed for networks that block or detect VPN traffic. Providers like Proton VPN and Windscribe label the protocol as “Stealth” in their apps, though other providers usually call it obfuscation (or obfuscated servers). It’s sometimes referred to as scrambling, protocol wrapping, cloaking, or a branded name like NordWhisper from NordVPN.

While there are several ways to achieve obfuscation, they all aim to disguise VPN traffic so it looks like normal HTTPS traffic. Instead of showing clear VPN patterns, the traffic blends in with everyday browsing and bypasses firewalls (including systems like the Great Firewall of China).

How does the Stealth VPN protocol work?

Windscribe’s Stealth works by running OpenVPN through an extra SSL layer using Stunnel. This open-source tool wraps network traffic inside TLS/SSL encryption, so filters see something that looks like normal secure web browsing instead of a VPN handshake.

Since Stealth mimics HTTPS traffic, blocking it would also block huge parts of the modern web, so most networks avoid doing that. Windscribe also supports multiple ports, including port 443, which is usually left open because websites rely on it.

Proton VPN’s Stealth protocol is essentially WireGuard wrapped in an obfuscated TLS tunnel over TCP, which can help it blend in better than protocols that rely on UDP. Proton also claims it connects in a “unique” way that avoids tipping off internet filters, but it doesn’t go into detail (presumably to avoid making it easier to block).

Related: UDP vs TCP: What are they and how do they differ?

Other providers use SSH encryption for obfuscation, while some scramble VPN metadata, rewriting packet details to make the traffic look like normal HTTPS data.

How to use the Stealth VPN protocol

Each provider has its own way of activating Stealth mode. Here are some examples:

Proton VPN

  1. Open the Proton VPN app on your device and go to Settings.
  2. Choose Connection (Advanced on Android and Security options on iOS).
  3. Select Protocol and activate Stealth.

Windscribe

  1. Launch Windscribe on your device and go to Preferences.
  2. Press the menu icon (☰) on the top-left.
  3. Go to Connection.
  4. Click the Connection Mode drop-down and pick Manual.
  5. Next, click the Protocol option and select Stealth.

NordVPN

  1. Open NordVPN, click your profile icon, and select Settings.
  2. Go to Connection and security and choose OpenVPN TCP or UDP.
  3. Return to the home screen and press All locations.
  4. Select Obfuscated and connect to your preferred location.

On other VPN apps, you can typically find the Stealth/obfuscation feature under “Connection” or protocol settings.

Pros and cons of the Stealth VPN protocol

The Stealth VPN protocol can help when networks block normal VPN traffic, but it also comes with some trade-offs. Here’s what to expect.

Benefits

  • Bypasses VPN blocks: Stealth hides VPN traffic, making it harder for firewalls and filters to spot and block your connection.
  • Works in restrictive countries: It can help you connect in countries that ban VPNs or inspect traffic closely with deep packet inspection (DPI) or other techniques.
  • Better privacy on monitored networks: Stealth makes it harder for network admins or ISPs to tell you’re using a VPN at all.
  • More stable access in rare cases: Some networks drop normal VPN connections, so Stealth can reduce the number of random disconnects.

Drawbacks

  • Slower speeds: Stealth adds extra steps to disguise traffic (like an additional layer of encryption with Stunnel), so downloads and streaming may feel slower than WireGuard or standard OpenVPN.
  • Higher battery use: The extra processing can drain your phone battery faster, especially during long sessions.
  • Limited server support: Some VPNs only offer stealth capabilities on certain servers, which can reduce your location options.
  • Not always needed: On normal home networks, standard protocols usually work fine, so Stealth can add slowdown without much benefit.
  • Not guaranteed to work: If the service or network blocks the VPN server’s IP address itself, Stealth or other obfuscation methods won’t help.

When should I use the Stealth protocol?

Here are some situations where using the Stealth protocol is a good idea:

  • For extra privacy on restrictive networks: If you want your VPN traffic to look like normal HTTPS browsing, Stealth makes detection harder. This can help on networks that monitor VPN use, even if they don’t fully block it.
  • On public Wi-Fi with VPN blocks: Some hotels, airports, and cafes block or slow down VPN traffic to control bandwidth. Stealth can help your connection blend in, so you can browse normally without random disconnects or speed drops.
  • On corporate or school networks: Workplaces and campuses often use firewalls to restrict VPN apps and limit what you can access. Stealth can help you connect anyway, especially when standard VPN protocols get flagged or blocked.
  • In censorship-heavy regions: Countries like China, the UAE, and Iran block or heavily restrict VPN usage, leaving Stealth protocols as your only option to access the free internet.
  • Other protocols don’t work: For basic privacy and everyday tasks, a protocol like OpenVPN or WireGuard should do the trick. Try Stealth if your network blocks them or you’re facing connectivity issues with other protocols.

What is the Stealth VPN protocol? FAQs

Can you be tracked if you use a Stealth VPN protocol?

Stealth VPN protocols can reduce tracking by hiding the fact that you’re using a VPN in the first place. Still, websites and apps can track you through things like cookies, logins, and browser fingerprinting, even if your VPN traffic looks normal on the network.

Does Stealth work for torrenting or streaming?

Stealth can work for torrenting or streaming by helping your VPN connection get past blocks that target VPN traffic. That said, streaming sites may still detect VPN IP addresses, and torrenting depends more on having P2P support and a reliable kill switch. Not to mention Stealth is usually slower than regular protocols.

Is the Stealth protocol better than WireGuard?

Both protocols have their own uses. The Stealth protocol can be better than WireGuard when you need to bypass VPN blocks or deep packet inspection. Meanwhile, WireGuard wins in terms of speed, so it’s often the better option if your network allows normal VPN traffic.

You can even use projects like udptunnel or udp2raw to apply obfuscation to WireGuard traffic if you prefer a DIY setup, though Proton VPN’s Stealth protocol already uses a TLS wrapper to disguise WireGuard.

Which VPNs have a Stealth protocol?

VPNs like Proton VPN and Windscribe actually use the name “Stealth” to describe their obfuscation protocol. That said, many VPNs offer similar tech, but either just call it “obfuscated servers” (like NordVPN) or have their own take on it (e.g., Surfshark’s “Camouflage Mode”).