Trojan vs VLESS Reality: which one to use in 2026

We ran Trojan for years, moved stealth to VLESS Reality, and brought Trojan back as a legacy option for Clash apps. An honest comparison from a provider that runs both.

By the VPNBaron teamUpdated 2 October 2026 · 5 min read

A dotted globe in deep blue, with connections arcing between points on it

Most protocol comparisons are written from spec sheets. This one isn’t: we ran Trojan in production for years, on real servers with real users behind real firewalls, and then moved our stealth traffic to VLESS Reality. Trojan is still here, as a legacy option for Clash apps. Here’s what each protocol actually is, why stealth moved to Reality, and which one to use today.

Head to head

Trojan VLESS Reality
Core idea Hide inside self-hosted TLS on port 443 Present a real third-party site’s TLS on port 443
Needs its own domain + certificate Yes: registered, renewed, per deployment No: it borrows the handshake of an existing well-known site
SNI inspection Sees your (unknown, often young) domain Sees a normal, reputable site
Active probing Exposed: the endpoint answers for itself and can be confirmed Survives: probes receive the genuine website back
Speed Lightweight, TCP 443 Lightweight, TCP 443, small camouflage cost
Operational burden (server side) Domains, certs, renewals, rotation No certificate estate to maintain
Status in 2026 Works on lenient networks, ecosystem in decline Current default of the Xray ecosystem
At VPNBaron Legacy option for Clash apps (TCP 8443) Stealth, in the app and the Stealth subscription

Why stealth moved to Reality

Trojan was a genuinely good design for its era, and it carried our stealth users for years. But operating it honestly means admitting its two structural problems.

The certificate estate. Every Trojan deployment needs a real domain with a real certificate. Domains age, look suspicious when young, appear in transparency logs, and must be rotated when burned. At fleet scale that’s a permanent operational tax, and every shortcut weakens the disguise.

The probing hole. When a censor suspects an endpoint, it connects and pokes. A Trojan server ultimately answers for itself, and careful probing can confirm what it is. This is the technique that retired a whole generation of look-like-TLS protocols, and it’s rung five of the detection ladder we describe in What is deep packet inspection.

Reality solved both at once: there is no certificate to own because the server presents a real site’s handshake, and a probe gets that real site’s content back. Nothing to renew, nothing that confesses. The VLESS Reality protocol page covers how we run it.

tshark output in a terminal: a VLESS Reality connection to a VPNBaron server appears only as TLS Client Hello packets with SNI www.apple.com
A VLESS Reality connection to one of our servers, seen from the network: TLS Client Hello packets for www.apple.com. No domain or certificate of ours appears anywhere.

Why Trojan is back, as a legacy option

Plenty of people still use Clash for Windows, ClashX and other classic Clash apps, and those apps can’t do Reality. So in September 2026 we brought Trojan back for them: a Trojan-only profile for Clash apps, on port 8443. It works on most networks and in any Clash app, but it doesn’t change the verdict above: it’s easier to detect than Reality, so it’s not the one to use on a network that’s hunting VPNs.

Your Clash link is on the Trojan page of your account. Setup guides: Windows, macOS.

Which one should you use?

On a lenient network, in a Clash app you like, Trojan is fine. There’s no emergency on a network that isn’t hunting you. But the practical move is to have Reality ready before you need it, and it costs nothing to set up alongside.

Your client almost certainly already speaks it: sing-box based apps (V2Box, Hiddify) and Clash Meta handle Trojan, VLESS Reality and Hysteria2 side by side. A VPNBaron stealth subscription carries Reality and Hysteria2 entries for every location (plus the legacy Trojan ones): Reality for networks that inspect, Hysteria2 for speed on bad links. Import guides: V2Box, Hiddify.

A VPNBaron stealth subscription in Hiddify, listing VLESS and Hysteria2 entries for each location with their latencies
A VPNBaron stealth subscription in Hiddify: a VLESS Reality and a Hysteria2 entry for each location.

And if you’d rather stop thinking about protocols entirely, the VPNBaron app runs the whole stack natively. Baron Pathfinder tests routes on your current network and settles on whatever connects, without you juggling entries.

Baron Pathfinder in the VPNBaron Linux app, connected via VLESS Reality after testing the protocols
Baron Pathfinder in the VPNBaron app, settled on VLESS Reality for this network.

VPNBaron

Keep your Clash app, add Reality when you need it

Reality and Hysteria2 on every location, plus Trojan for Clash apps: import the subscription into the client you already use, or let the app handle protocols entirely. Test it on the network where Trojan started failing you.

FAQ

Is Trojan obsolete in 2026? Superseded for stealth. It connects on lenient networks and in every Clash app, but its certificate requirement and probing exposure are why the ecosystem moved to Reality.

Does VPNBaron still support Trojan? Yes, as a legacy option for Clash apps, on port 8443. Your Clash link is on the Trojan page. For networks that block VPNs, use Reality or Hysteria2.

Is VLESS Reality faster than Trojan? Comparable: both are lightweight TCP 443 proxies. The switch buys survivability, not speed. For speed on lossy networks, that’s Hysteria2’s job.

Why did providers drop Trojan? Certificate and domain upkeep per server, plus endpoints that can be confirmed by active probing. Reality removes both.

Do I need a domain or certificate for Reality? As a user, no. Nothing to register or renew: import a subscription and connect.

My provider still hands out Trojan configs. What now? Keep them as fallback, add Reality alongside in the same client, and switch entries the day a network starts eating your Trojan connection.

More in VPN protocols·Related: Stealth VPN

Keep reading

A dotted globe in light blue, with connections arcing between points on it

VPN protocols

Which VPN protocol should you use?

How VLESS Reality, Hysteria2, IKEv2 and OpenVPN compare, and when the choice of protocol actually matters.

28 September 2026 · 3 min read