Why Outline / Shadowsocks Is Getting Easier to Detect in Iran: An Honest Comparison and a Probe-Resistant Alternative (VLESS+Reality)
Updated
Why Outline is getting easier to detect in Iran
Outline is a one-click, foolproof tool from Jigsaw (part of Google's parent company) and it's deservedly popular. But to understand its situation you have to know one thing first: Outline uses the Shadowsocks protocol under the hood. Shadowsocks has a set of recognizable traffic characteristics — typically a rhythm of "a few small control packets, then a burst of large data packets." Over the years Iran's DPI has grown very familiar with this signature and, paired with machine learning, reportedly hits 80–95% accuracy. The result: domain-based or self-hosted Outline nodes often "get throttled or outright blacklisted within days." This usually isn't a setup mistake on your end — it's the combination of Shadowsocks's fixed fingerprint plus Iran's targeted probing.
Outline's strengths (stated honestly)
Credit where it's due: Outline is free, open source, extremely simple, and self-hostable on your own overseas server. And one key fact deserves honesty: during Iran's massive 2025 blackout, many Outline nodes people had stood up in Turkey and Germany still passed nationwide DPI filtering — as long as the client and node were installed before the blackout — while huge numbers of commercial VPN domains simply vanished. So don't throw Outline away: it's zero-barrier, self-hostable, and still a lifeline if preinstalled before a blackout; it just loses ground against day-to-day active probing.
How Iran's DPI actually catches Shadowsocks (and when to switch)
Iran mainly uses two moves. First, active probing: when DPI suspects a server is a proxy, it connects to it and attempts a Shadowsocks handshake, and if the server behaves "like Shadowsocks" it gets blacklisted — reportedly how most Shadowsocks / Trojan servers are eventually caught. Second, statistical fingerprinting: machine learning on packet sizes and timing to spot Shadowsocks's "small control packets + large data packets" pattern. When you notice nodes that "die within days," get "throttled until pages won't load," or you need long, stable sessions, it's time to switch to a channel that is inherently hard for active probing to catch — otherwise more backup nodes just get picked off one by one.
The probe-resistant alternative: VLESS + Reality
VLESS is a lean transport protocol and Reality is its TLS camouflage layer. The fundamental difference from Shadowsocks: Shadowsocks is "encrypted but still looks like a proxy," whereas Reality makes your handshake a genuine TLS handshake to a real, public, major website. That yields two direct benefits: ① when DPI actively probes your server, it gets a real certificate and real website behavior — there's no "proxy signature" to blacklist; ② your traffic shape is already real HTTPS, so statistical fingerprinting has nothing to match. On top of that, VLESS+Reality uses a dedicated node, faster and more stable than shared public Outline. The honest trade-off: it isn't zero-barrier like Outline — you need a subscription and a client (sing-box / v2rayN / Shadowrocket, etc.); and no approach can guarantee it always works — during a nationwide blackout no cross-border channel connects at all.
How to migrate from Outline: step by step
- Copy your subscription link from the dashboard (prefer VLESS+Reality nodes in Iran).
- Install a mature client: Shadowrocket on iOS, sing-box or v2rayN on Android / desktop, and import the subscription URL (don't add a single node by hand).
- Update the subscription, run a latency test, and enable a low-latency node.
- Use Rule mode: send Iranian bank / government apps direct (they reject foreign IPs) and route only blocked services through the tunnel.
- Keep a preinstalled Outline as a blackout / emergency backup — especially if the client and node are installed before a blackout, it may still squeeze out an emergency channel.
Honest expectations
- No tool can guarantee it always works everywhere; Reality lowers the odds of automatic detection, but the real outcome depends on node quality and operations.
- During a nationwide blackout, any cross-border channel (VLESS and Outline alike) may fail to connect — that's unrelated to the protocol.
- The recommendation is "use VLESS+Reality as your primary for speed and probe resistance, keep a preinstalled Outline for blackout emergencies" — not either/or.
- For comparisons of the other free tools see why Psiphon slows down and its alternative and why Cloudflare WARP gets throttled and its alternative; for the protocol primer see What is VLESS Reality; for client setup see sing-box setup for Persian users; for the overall comparison see what still works in Iran in 2026.
Follow local laws and third-party service terms; this is a technical explainer, responsibility for safe and lawful use rests with the user, and we cannot guarantee the long-term availability of any third-party service (including Outline).
FAQ
- Is Outline the same as Shadowsocks?
- Essentially yes. Outline is a foolproof wrapper made by Jigsaw, and it uses the Shadowsocks protocol under the hood — so it carries Shadowsocks's recognizable traffic characteristics. That's the root reason it's increasingly caught by DPI active probing in Iran.
- Is Outline banned in Iran?
- It isn't banned as a whole app; rather, its underlying Shadowsocks traffic is increasingly caught by DPI active probing and statistical fingerprinting, so nodes often get throttled or blacklisted within days — especially domain-based or self-hosted ones. A preinstalled Outline can still be usable during a blackout.
- Should I keep Outline after switching to VLESS?
- Yes, keep it — especially install the client and node before a blackout. During Iran's massive 2025 blackout, preinstalled Outline nodes still passed nationwide DPI and made a great emergency backup. Treat it as a blackout backup, not your daily primary.
- Why is Reality harder to detect than Outline?
- Because Reality makes your traffic a genuine TLS handshake to a real, public major website, so active probing gets a real certificate and real website behavior with no proxy signature to blacklist; Outline's Shadowsocks, by contrast, has a fixed traffic fingerprint that both active probing and statistical analysis catch more easily.
The service you're trying to reach is blocked. Restore access — free.
Back online in about 2 minutes — no credit card. A working VLESS + Reality route on iOS, Android, Windows and macOS.
- Free 1 GB/day
- No credit card
- VLESS + Reality in 60 seconds
You and your friend each get +30 bonus days plus bonus traffic once they start using Univista.
Restore access — freeRelated guides
Why Psiphon Keeps Getting Slower in Iran: An Honest Comparison and a Faster Alternative (VLESS+Reality)
Why Cloudflare WARP (1.1.1.1) Gets Throttled or Won't Connect in Iran: An Honest Explainer and a More Reliable Alternative (VLESS+Reality)
What Is VLESS + Reality? The Anti-Censorship Protocol Explained (2026)
For Iranian Users: Install sing-box and Import Your Univista Subscription
What Still Works in Iran in 2026: Why DPI Breaks Common VPNs and Why Protocol Choice Matters
Why Tor Won't Connect in Iran — And a Faster Alternative for Access (VLESS+Reality)
Share this guide
Already subscribed? Help for import & troubleshooting.
Ready for reliable international access?
View plansThis article is for technical education only. Comply with local laws when using network tools. Univista is not liable for how you use the service.