Trojan vs VLESS Reality: which one to use in 2026
We ran Trojan for years, moved stealth to VLESS Reality, and brought Trojan back as a legacy option for Clash apps. An honest comparison from a provider that runs both.
By the VPNBaron team · Updated 2 October 2026 · 5 min read

Most protocol comparisons are written from spec sheets. This one isn’t: we ran Trojan in production for years, on real servers with real users behind real firewalls, and then moved our stealth traffic to VLESS Reality. Trojan is still here, as a legacy option for Clash apps. Here’s what each protocol actually is, why stealth moved to Reality, and which one to use today.
Head to head
| Trojan | VLESS Reality | |
|---|---|---|
| Core idea | Hide inside self-hosted TLS on port 443 | Present a real third-party site’s TLS on port 443 |
| Needs its own domain + certificate | Yes: registered, renewed, per deployment | No: it borrows the handshake of an existing well-known site |
| SNI inspection | Sees your (unknown, often young) domain | Sees a normal, reputable site |
| Active probing | Exposed: the endpoint answers for itself and can be confirmed | Survives: probes receive the genuine website back |
| Speed | Lightweight, TCP 443 | Lightweight, TCP 443, small camouflage cost |
| Operational burden (server side) | Domains, certs, renewals, rotation | No certificate estate to maintain |
| Status in 2026 | Works on lenient networks, ecosystem in decline | Current default of the Xray ecosystem |
| At VPNBaron | Legacy option for Clash apps (TCP 8443) | Stealth, in the app and the Stealth subscription |
Why stealth moved to Reality
Trojan was a genuinely good design for its era, and it carried our stealth users for years. But operating it honestly means admitting its two structural problems.
The certificate estate. Every Trojan deployment needs a real domain with a real certificate. Domains age, look suspicious when young, appear in transparency logs, and must be rotated when burned. At fleet scale that’s a permanent operational tax, and every shortcut weakens the disguise.
The probing hole. When a censor suspects an endpoint, it connects and pokes. A Trojan server ultimately answers for itself, and careful probing can confirm what it is. This is the technique that retired a whole generation of look-like-TLS protocols, and it’s rung five of the detection ladder we describe in What is deep packet inspection.
Reality solved both at once: there is no certificate to own because the server presents a real site’s handshake, and a probe gets that real site’s content back. Nothing to renew, nothing that confesses. The VLESS Reality protocol page covers how we run it.

Why Trojan is back, as a legacy option
Plenty of people still use Clash for Windows, ClashX and other classic Clash apps, and those apps can’t do Reality. So in September 2026 we brought Trojan back for them: a Trojan-only profile for Clash apps, on port 8443. It works on most networks and in any Clash app, but it doesn’t change the verdict above: it’s easier to detect than Reality, so it’s not the one to use on a network that’s hunting VPNs.
Your Clash link is on the Trojan page of your account. Setup guides: Windows, macOS.
Which one should you use?
On a lenient network, in a Clash app you like, Trojan is fine. There’s no emergency on a network that isn’t hunting you. But the practical move is to have Reality ready before you need it, and it costs nothing to set up alongside.
Your client almost certainly already speaks it: sing-box based apps (V2Box, Hiddify) and Clash Meta handle Trojan, VLESS Reality and Hysteria2 side by side. A VPNBaron stealth subscription carries Reality and Hysteria2 entries for every location (plus the legacy Trojan ones): Reality for networks that inspect, Hysteria2 for speed on bad links. Import guides: V2Box, Hiddify.

And if you’d rather stop thinking about protocols entirely, the VPNBaron app runs the whole stack natively. Baron Pathfinder tests routes on your current network and settles on whatever connects, without you juggling entries.

VPNBaron
Keep your Clash app, add Reality when you need it
Reality and Hysteria2 on every location, plus Trojan for Clash apps: import the subscription into the client you already use, or let the app handle protocols entirely. Test it on the network where Trojan started failing you.
FAQ
Is Trojan obsolete in 2026? Superseded for stealth. It connects on lenient networks and in every Clash app, but its certificate requirement and probing exposure are why the ecosystem moved to Reality.
Does VPNBaron still support Trojan? Yes, as a legacy option for Clash apps, on port 8443. Your Clash link is on the Trojan page. For networks that block VPNs, use Reality or Hysteria2.
Is VLESS Reality faster than Trojan? Comparable: both are lightweight TCP 443 proxies. The switch buys survivability, not speed. For speed on lossy networks, that’s Hysteria2’s job.
Why did providers drop Trojan? Certificate and domain upkeep per server, plus endpoints that can be confirmed by active probing. Reality removes both.
Do I need a domain or certificate for Reality? As a user, no. Nothing to register or renew: import a subscription and connect.
My provider still hands out Trojan configs. What now? Keep them as fallback, add Reality alongside in the same client, and switch entries the day a network starts eating your Trojan connection.
Related guides
- Trojan setup with Clash: Windows, macOS
- VLESS Reality protocol
- Hysteria2 vs VLESS Reality: which one and when
- Shadowsocks vs VLESS Reality
- What deep packet inspection actually does
More in VPN protocols·Related: Stealth VPN

