VPNs That Work in China - The Reality

The Great Firewall detects plain WireGuard and OpenVPN handshakes and cuts them. What survives in 2026 is VLESS+Reality, AmneziaWG, Shadowsocks-2022 and some commercial obfuscated servers - configured and tested before arrival, with at least two backups.

China is the hardest test in the industry and the one most marketing lies about. The Great Firewall detects plain WireGuard and OpenVPN at the handshake, throttles known tunneling patterns, and rotates its detection methods around politically sensitive dates [3]. What works is not a brand - it is a protocol stack with real obfuscation, configured before you land.

Unauthorized VPNs have required state approval since 2017, and the Ministry of State Security warned again in November 2025 that using circumvention tools is illegal [2]. In practice enforcement focuses on sellers and heavy users; millions of residents and visitors use tunnels daily. But the law exists, the 2025 MSS warning lowered the tolerance, and anyone whose circumstances attract attention should read a real threat model rather than a VPN affiliate's reassurance.

What actually survives (2025-2026)

Per current blocking research and OONI data [1][3]:

  • VLESS + Reality: currently the most resilient mainstream stack - it borrows the TLS fingerprint of a real site visit.
  • AmneziaWG: WireGuard with obfuscation layers; the practical self-hosted answer [4].
  • Shadowsocks-2022: alive but wave-blocked during sensitive periods.
  • Hysteria2: QUIC-based, throttled but functional outside crackdowns.
  • obfs4 bridges / Snowflake / meek: slow but structurally hard to enumerate.
  • Dead: plain OpenVPN (handshake-detected), PPTP, plain WireGuard, and most commercial VPNs' default configurations.

What the providers actually offer

Astrill's StealthShell/OpenWeb has been the China-expat staple for years and is priced accordingly ($300/2yr, no refunds). NordVPN, Proton (Stealth), Surfshark and Windscribe ship obfuscated-server modes with varying 2026 track records - verify current status close to travel, because endpoint rotation means "worked last month" proves nothing [1]. Providers that do not ship obfuscation are irrelevant for this use case no matter their server-count banner.

The operational playbook

  1. Before departure: install the apps (they vanish from stores inside China), test every method from home, and configure at least two independent paths - one commercial, one self-hosted [4].
  2. Offline copies: maps, translations, tickets, contacts - nothing that requires a login to reach.
  3. During the stay: expect outages around meetings and anniversaries; do not panic-switch protocols at the first slowdown, and keep a eSIM with a second country's data path as the escape hatch.
  4. Assume metadata visibility: tunnels fail; devices get searched; behavior inside the country is observable. Nothing here is legal advice.

The honest summary

There is no "best VPN for China" in the way the affiliate lists mean it. There are obfuscation stacks that currently work and brands that rotate fast enough to serve them - and the setup discipline matters more than either. Start from the alternatives guide for the self-hosted path, check the country page for the current legal picture, and treat every provider claim with a test date on it rather than a testimonial.

The sensitive-date calendar, operationally

The Great Firewall's enforcement is rhythmic, not random: blocking tightens around plenum sessions, major anniversaries and political meetings, then relaxes [1][3]. The practical consequences for a traveler are predictable and manageable:

  • Before a known sensitive window: refresh every endpoint, re-test each method, and expect the strictest configuration to degrade. The providers that ship obfuscation usually rotate harder in these windows.
  • Do not panic-switch: the most common self-inflicted failure is dropping a working method for a "better" one mid-crackdown, ending with zero working paths. Keep the one that works, prepare the backup offline.
  • Two-device rule: keep one device on the tunnel and one clean of anything sensitive - searches are rare for tourists but device inspection is not zero-risk, and a clean device ends that conversation quickly.

Nothing in this guide is legal advice; the legal picture is on the country page with sources and dates, and it changed in November 2025 when the MSS publicized its warning [2].

What we tell people to actually pack

Two independent methods tested at home on every device (one commercial provider with genuine obfuscation, one self-hosted AmneziaWG or VLESS/Reality on the same cheap VPS), eSIM from a second country as the escape hatch, offline copies of everything critical, and the discipline to not test new tools from inside the country. That is the entire difference between the travelers who get through and the ones writing "VPN stopped working on day two" posts.

For the protocol details start with the alternatives guide; for choosing a commercial account judge logging evidence and the provider's endpoint-rotation track record - not the affiliate top-10 that recommended the same five brands that dominate the Google results.

// FAQ

Is using a VPN illegal in China?

Unauthorized VPN services are illegal since 2017 rules requiring state approval, and the MSS warned again in November 2025 that circumvention is illegal. Ordinary tourists are rarely charged, but the legal risk is real and nonzero.

Which commercial VPNs work in China right now?

The ones that ship genuine obfuscation and rotate endpoints fast - Astrill's StealthVPN, providers with VLESS/Reality or obfuscated server options. No provider offers a guarantee; every service has outages during crackdowns.

Does a free VPN work in China?

Almost never. Free apps use detectable protocols, their IPs are blocked, and their business model involves looking at your traffic. Use Tor bridges or a configured obfuscated server instead.

What should I set up before flying?

Install and test at least two working methods on every device (a provider with obfuscation plus VLESS/Reality or AmneziaWG self-hosted), plus offline copies of everything you need. App stores inside China will not help you.

// Sources

  1. OONI - open measurements of internet censorship (China data) - accessed 2026-09-27
  2. Ministry of State Security warning on illegal circumvention (Nov 2025 coverage) - accessed 2026-09-27
  3. GFW Report - technical analysis of protocol blocking - accessed 2026-09-27
  4. Amnezia - obfuscation methods for censored networks - accessed 2026-09-27

// Related