# When Should You Use Zapret's FAKE TLS AUTO Strategy?

> When should you use Zapret's FAKE TLS AUTO strategy? Discover when to employ this aggressive DPI evasion technique for heavily inspected TLS connections like YouTube and Discord when simpler methods fail.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: best-practices
- Published: 2026-05-02

---

**Use Zapret's FAKE TLS AUTO strategy only when lighter DPI-evasion profiles fail—it is the most aggressive configuration designed for heavily inspected TLS connections to services like YouTube and Discord.**

Zapret is a deep-packet inspection (DPI) circumvention tool from the Flowseal/zapret-discord-youtube repository that uses WinDivert to modify network traffic on Windows. The FAKE TLS AUTO strategy represents the nuclear option in its arsenal, combining fake-TLS fragmentation, QUIC spoofing, and aggressive desynchronization to bypass sophisticated firewalls that recognize simpler evasion methods.

## What Makes FAKE TLS AUTO Different

Unlike lighter profiles such as **ALT** or **SIMPLE FAKE**, the FAKE TLS AUTO strategy injects the strongest fake-TLS payloads—including `0x00000000` and `!` sequences—while randomizing the Server Name Indication (SNI) field with values like `www.google.com`. According to the source code in `general (FAKE TLS AUTO).bat`, this profile loads specialized binary payloads from `bin/quic_initial_www_google_com.bin` and `bin/quic_initial_dbankcloud_ru.bin` to confuse DPI engines that hunt for exact TLS signatures.

The strategy applies desynchronization across **all** monitored TCP ports (80, 443, 2053, 2083, 2087, 2096, 8443) and UDP ranges (443, 19294-19344, 50000-50100), while respecting the `%GameFilterTCP%` and `%GameFilterUDP%` variables to avoid disrupting gaming traffic.

## Four Situations That Require FAKE TLS AUTO

### All Other Strategies Have Failed

If you have exhausted alternatives like **ALT**, **SIMPLE FAKE**, or **MIX**, and traffic still gets blocked by your ISP's DPI system, switch to FAKE TLS AUTO. This profile adds layered obfuscation that defeats DPI systems trained to recognize the lighter-weight signatures used by other modes.

### Targeting Heavily Inspected TLS Services

YouTube, Discord, and major cloud providers often employ aggressive middlebox inspection of TLS handshakes. FAKE TLS AUTO specifically targets these environments by injecting fake-QUIC client-hello packets and fragmenting the initial TLS handshake using `bin/tls_clienthello_max_ru.bin` payloads, which breaks signature-based detection.

### Managing Multi-Protocol Traffic Automatically

When you need simultaneous coverage for both TCP and UDP traffic across diverse port ranges without manual configuration, this strategy functions as a catch-all. The batch file automatically configures `winws.exe` with `--dpi-desync` arguments covering the full port spectrum used by modern web services and voice applications.

### Deploying a Set-and-Forget Profile

The command line in `general (FAKE TLS AUTO).bat` includes the `--new` flag, which restarts the WinDivert driver with the updated rule set immediately. This ensures the configuration persists as a persistent service until explicitly stopped, eliminating the need to relaunch the script after reboots.

## Performance and Security Trade-Offs

Because FAKE TLS AUTO manipulates packets at multiple layers using complex fragmentation rules, it increases **CPU load** compared to simpler strategies. Additionally, since the tool relies on WinDivert (a Windows packet diversion driver), some antivirus products flag the executable as suspicious. You should monitor system resources after activation and consider adding an exclusion for `bin/winws.exe` if you trust the source.

## How to Deploy the Strategy

### Launch Manually

Open an elevated command prompt and execute the batch file directly:

```bat
"general (FAKE TLS AUTO).bat"

```

This sequence loads the current service status, pulls the latest game-filter lists, and launches `winws.exe` with the full DPI-desync command chain.

### Install as a Windows Service

To make the profile persistent across reboots, use the service helper:

```bat
service.bat

```

Select **Install Service**, then choose **FAKE TLS AUTO** from the interactive list. The script registers `winws.exe` with the Windows service manager, enabling automatic startup.

### Switch Profiles on the Fly

You can migrate to a different strategy without rebooting by removing the current service and launching a new batch:

```bat
service.bat Remove Services
"general (FAKE TLS AUTO).bat"

```

## Key Configuration Files

The FAKE TLS AUTO profile relies on the following components from the Flowseal/zapret-discord-youtube repository:

- **`general (FAKE TLS AUTO).bat`** — Main launcher containing the DPI-desync command line with fake-TLS and fake-QUIC arguments.
- **`service.bat`** — Helper script for installing, removing, and diagnosing the Windows service.
- **`bin/winws.exe`** — The WinDivert-based packet interceptor that applies the filtering rules to live traffic.
- **`bin/quic_initial_www_google_com.bin`** — Fake QUIC client-hello payload used to obfuscate connection attempts.
- **`bin/quic_initial_dbankcloud_ru.bin`** — Secondary fake QUIC payload optimized for Discord-related traffic.
- **`bin/tls_clienthello_max_ru.bin`** — Fake TLS ClientHello fragment injected into HTTPS handshakes.
- **[`lists/list-general.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/list-general.txt)** — Default domain whitelist consulted during filtering.
- **[`lists/ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-all.txt)** — Comprehensive IP set for UDP/TCP range filtering.

## Summary

- **Use FAKE TLS AUTO** as a last resort when ALT, SIMPLE FAKE, and other lightweight strategies fail to bypass your ISP's DPI.
- The strategy injects fake-TLS and fake-QUIC payloads from `bin/quic_initial_www_google_com.bin` and `bin/tls_clienthello_max_ru.bin` to break signature detection.
- It covers broad port ranges (TCP 80,443,2053,2083,2087,2096,8443 and UDP 443,19294-19344,50000-50100) while respecting game filters.
- Deploy via `"general (FAKE TLS AUTO).bat"` for temporary use or `service.bat` for permanent installation.
- Expect higher CPU usage and potential antivirus warnings due to WinDivert driver activity.

## Frequently Asked Questions

### What's the difference between FAKE TLS AUTO and other Zapret strategies?

**FAKE TLS AUTO** is significantly more aggressive than profiles like ALT or SIMPLE FAKE. While lighter strategies might only split packets or modify TTL fields, FAKE TLS AUTO injects synthetic TLS and QUIC handshakes using binary payloads from the `bin/` directory, making it effective against DPI systems that have learned to recognize simpler evasion patterns.

### Why does my antivirus flag FAKE TLS AUTO?

The strategy relies on `bin/winws.exe`, which utilizes the WinDivert driver to intercept and modify network packets at the kernel level. This behavior pattern matches rootkit signatures used by some malware, causing heuristic detection by antivirus software. The official Flowseal/zapret-discord-youtube repository provides the legitimate source, but you may need to add an exclusion for the `bin/` directory to prevent interference.

### Can I use FAKE TLS AUTO for competitive gaming?

While the strategy includes `%GameFilterTCP%` and `%GameFilterUDP%` variables designed to exclude game traffic from DPI manipulation, the intensive packet processing can still introduce latency. For competitive gaming, start with lighter strategies first, and only use FAKE TLS AUTO if you can tolerate slightly higher CPU overhead and have verified that your specific game ports are properly excluded in [`lists/list-exclude.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/list-exclude.txt).

### How do I revert to a lighter strategy after using FAKE TLS AUTO?

Run `service.bat Remove Services` to stop and unregister the current service, then launch your preferred alternative batch file (such as `general (ALT).bat`). The `--new` flag used by FAKE TLS AUTO ensures the WinDivert driver restarts cleanly with the new rule set, so no system reboot is required when switching between profiles.