Which VPN works in Russia right now — a brief breakdown
Short answer: what “works” right now is not a VPN in general, but a specific protocol through a specific operator. The same service can run without interruption on one provider and be completely down on another. What matters is not the service’s marketing, but the masking protocol: VLESS Reality, Hysteria, Shadowsocks with obfs, AmneziaWG.
Below is not a breakdown of “which exact service to buy” (that changes week by week), but which classes of protocols are currently more stable through TSPU, what is changing, and how to check the situation for your own operator. If you need a general overview of the topic, there is a separate article — which VPN works in Russia right now.
The main point: a VPN that “works right now” is a combination of a masking protocol and a server that is not blocked by your operator. The service is secondary.
In short
- Open signatures — plain WireGuard, OpenVPN, L2TP, PPTP — are already unstable on some operators.
- Masking protocols — VLESS Reality, Hysteria, Shadowsocks 2022 — continue to work in most regions.
- AmneziaWG — a WireGuard modification with signature hiding — is more stable than “plain” WireGuard on Russian operators.
- MTProxy for Telegram works by its own rules and often gets through where a general VPN does not.
- The situation changes every 1–4 weeks; there is no universal “best service,” only a protocol+server+operator combination.
What “works right now” means
In practice, “works” means four simultaneous conditions: (1) your operator has not blocked the server IP; (2) the protocol signature is not being cut off by TSPU; (3) DNS inside the tunnel resolves; (4) the server is not overloaded. If any one of the four fails, the VPN “does not work.”
Masking protocols are the main workhorse
Right now, the most stable protocols are those that disguise traffic as ordinary HTTPS. VLESS with Reality imitates the TLS handshake of a real existing website, so the traffic does not visibly look like “this is a VPN.” Hysteria 2 works over QUIC and is harder to detect in a mass filter. Shadowsocks 2022 (new ciphers) is easier to deploy and also survives on most operators.
Classic protocols are a lottery
Plain WireGuard and OpenVPN work on some operators and do not work on others. PPTP and L2TP/IPSec are blocked almost everywhere at the signature level. If you want WireGuard, it is worth looking at AmneziaWG, which adds random bytes to the handshake and bypasses most signature-based detectors.
What changes most often
Three things change: lists of blocked subnets at a specific operator, new DPI rules, and the availability of payment gateways for a specific service. A service may “stop working” not because it has been blocked, but because Russian-issued card payments stopped working — and you can no longer change the server without a subscription.
What usually works now, and what does not
| VPN class | Status on most operators | Note |
|---|---|---|
| VLESS + Reality | Works stably | Disguises itself as HTTPS, hard to detect |
| Hysteria 2 (QUIC) | Works stably | UDP, sensitive to connection quality |
| Shadowsocks 2022 | Works stably | Needs new ciphers, not old SS |
| AmneziaWG | Works for most users | More stable than “plain” WireGuard |
| WireGuard “as is” | Depends on the operator | Often blocked on mobile LTE |
| OpenVPN UDP/TCP | Depends on the operator | UDP is blocked more often than TCP/443 |
| L2TP / PPTP / IKEv2 without obfs | More often does not work | Signatures have long been in the filters |
| MTProxy for Telegram | Works by its own rules | Only for Telegram, not for all traffic |
How to check right now
Instead of relying on someone else’s experience, check your specific combination: operator + protocol + target site. Freedom Checker regularly measures availability through different providers — this gives you a picture of “your situation now,” not “someone else’s a month ago.”
If the same VPN works for a neighbor on another operator, but not for you, the issue is the filter of your specific operator, and changing the protocol is what matters. If it does not work for anyone, it is worth checking whether the service itself has failed.
Failure or blocking?
If the VPN worked yesterday but does not work today, and neither changing location nor restarting helps, this is most often blocking by the protocol signature. Only switching to a masking protocol helps.
If everything stopped working for everyone at once and across several services simultaneously, this is usually scheduled TSPU work or a mass blocking of the subnet these services are connected to. After a few hours, some services adapt; the rest do not.
What to look for when choosing
- A service without protocol selection is a bad choice; you need at least 2–3 options (Reality, Hysteria, WireGuard).
- There should be many servers in countries neighboring Russia; the more there are, the higher the chance of finding one that is not blocked.
- Clear instructions for changing the server and protocol without reinstalling the client.
- Do not pay for “100% bypass” — no honest provider gives such guarantees.
- It is useful to have a backup service on another protocol.
- The situation may differ by operator, region, and time of checking.
Conclusion
Which VPN works right now is not a question of the brand, but of the “protocol + server + operator” combination. Masking protocols are currently the most stable; “plain” WireGuard and OpenVPN have turned into a lottery.
Before buying, and when something fails, check your specific case, not the general picture.