When Should You Use Zapret's FAKE TLS AUTO Strategy?

Use Zapret's FAKE TLS AUTO strategy only when lighter DPI-evasion profiles fail—it is the most aggressive configuration designed for heavily inspected TLS connections to services like YouTube and Discord.

Zapret is a deep-packet inspection (DPI) circumvention tool from the Flowseal/zapret-discord-youtube repository that uses WinDivert to modify network traffic on Windows. The FAKE TLS AUTO strategy represents the nuclear option in its arsenal, combining fake-TLS fragmentation, QUIC spoofing, and aggressive desynchronization to bypass sophisticated firewalls that recognize simpler evasion methods.

What Makes FAKE TLS AUTO Different

Unlike lighter profiles such as ALT or SIMPLE FAKE, the FAKE TLS AUTO strategy injects the strongest fake-TLS payloads—including 0x00000000 and ! sequences—while randomizing the Server Name Indication (SNI) field with values like www.google.com. According to the source code in general (FAKE TLS AUTO).bat, this profile loads specialized binary payloads from bin/quic_initial_www_google_com.bin and bin/quic_initial_dbankcloud_ru.bin to confuse DPI engines that hunt for exact TLS signatures.

The strategy applies desynchronization across all monitored TCP ports (80, 443, 2053, 2083, 2087, 2096, 8443) and UDP ranges (443, 19294-19344, 50000-50100), while respecting the %GameFilterTCP% and %GameFilterUDP% variables to avoid disrupting gaming traffic.

Four Situations That Require FAKE TLS AUTO

All Other Strategies Have Failed

If you have exhausted alternatives like ALT, SIMPLE FAKE, or MIX, and traffic still gets blocked by your ISP's DPI system, switch to FAKE TLS AUTO. This profile adds layered obfuscation that defeats DPI systems trained to recognize the lighter-weight signatures used by other modes.

Targeting Heavily Inspected TLS Services

YouTube, Discord, and major cloud providers often employ aggressive middlebox inspection of TLS handshakes. FAKE TLS AUTO specifically targets these environments by injecting fake-QUIC client-hello packets and fragmenting the initial TLS handshake using bin/tls_clienthello_max_ru.bin payloads, which breaks signature-based detection.

Managing Multi-Protocol Traffic Automatically

When you need simultaneous coverage for both TCP and UDP traffic across diverse port ranges without manual configuration, this strategy functions as a catch-all. The batch file automatically configures winws.exe with --dpi-desync arguments covering the full port spectrum used by modern web services and voice applications.

Deploying a Set-and-Forget Profile

The command line in general (FAKE TLS AUTO).bat includes the --new flag, which restarts the WinDivert driver with the updated rule set immediately. This ensures the configuration persists as a persistent service until explicitly stopped, eliminating the need to relaunch the script after reboots.

Performance and Security Trade-Offs

Because FAKE TLS AUTO manipulates packets at multiple layers using complex fragmentation rules, it increases CPU load compared to simpler strategies. Additionally, since the tool relies on WinDivert (a Windows packet diversion driver), some antivirus products flag the executable as suspicious. You should monitor system resources after activation and consider adding an exclusion for bin/winws.exe if you trust the source.

How to Deploy the Strategy

Launch Manually

Open an elevated command prompt and execute the batch file directly:

"general (FAKE TLS AUTO).bat"

This sequence loads the current service status, pulls the latest game-filter lists, and launches winws.exe with the full DPI-desync command chain.

Install as a Windows Service

To make the profile persistent across reboots, use the service helper:

service.bat

Select Install Service, then choose FAKE TLS AUTO from the interactive list. The script registers winws.exe with the Windows service manager, enabling automatic startup.

Switch Profiles on the Fly

You can migrate to a different strategy without rebooting by removing the current service and launching a new batch:

service.bat Remove Services
"general (FAKE TLS AUTO).bat"

Key Configuration Files

The FAKE TLS AUTO profile relies on the following components from the Flowseal/zapret-discord-youtube repository:

  • general (FAKE TLS AUTO).bat — Main launcher containing the DPI-desync command line with fake-TLS and fake-QUIC arguments.
  • service.bat — Helper script for installing, removing, and diagnosing the Windows service.
  • bin/winws.exe — The WinDivert-based packet interceptor that applies the filtering rules to live traffic.
  • bin/quic_initial_www_google_com.bin — Fake QUIC client-hello payload used to obfuscate connection attempts.
  • bin/quic_initial_dbankcloud_ru.bin — Secondary fake QUIC payload optimized for Discord-related traffic.
  • bin/tls_clienthello_max_ru.bin — Fake TLS ClientHello fragment injected into HTTPS handshakes.
  • lists/list-general.txt — Default domain whitelist consulted during filtering.
  • lists/ipset-all.txt — Comprehensive IP set for UDP/TCP range filtering.

Summary

  • Use FAKE TLS AUTO as a last resort when ALT, SIMPLE FAKE, and other lightweight strategies fail to bypass your ISP's DPI.
  • The strategy injects fake-TLS and fake-QUIC payloads from bin/quic_initial_www_google_com.bin and bin/tls_clienthello_max_ru.bin to break signature detection.
  • It covers broad port ranges (TCP 80,443,2053,2083,2087,2096,8443 and UDP 443,19294-19344,50000-50100) while respecting game filters.
  • Deploy via "general (FAKE TLS AUTO).bat" for temporary use or service.bat for permanent installation.
  • Expect higher CPU usage and potential antivirus warnings due to WinDivert driver activity.

Frequently Asked Questions

What's the difference between FAKE TLS AUTO and other Zapret strategies?

FAKE TLS AUTO is significantly more aggressive than profiles like ALT or SIMPLE FAKE. While lighter strategies might only split packets or modify TTL fields, FAKE TLS AUTO injects synthetic TLS and QUIC handshakes using binary payloads from the bin/ directory, making it effective against DPI systems that have learned to recognize simpler evasion patterns.

Why does my antivirus flag FAKE TLS AUTO?

The strategy relies on bin/winws.exe, which utilizes the WinDivert driver to intercept and modify network packets at the kernel level. This behavior pattern matches rootkit signatures used by some malware, causing heuristic detection by antivirus software. The official Flowseal/zapret-discord-youtube repository provides the legitimate source, but you may need to add an exclusion for the bin/ directory to prevent interference.

Can I use FAKE TLS AUTO for competitive gaming?

While the strategy includes %GameFilterTCP% and %GameFilterUDP% variables designed to exclude game traffic from DPI manipulation, the intensive packet processing can still introduce latency. For competitive gaming, start with lighter strategies first, and only use FAKE TLS AUTO if you can tolerate slightly higher CPU overhead and have verified that your specific game ports are properly excluded in lists/list-exclude.txt.

How do I revert to a lighter strategy after using FAKE TLS AUTO?

Run service.bat Remove Services to stop and unregister the current service, then launch your preferred alternative batch file (such as general (ALT).bat). The --new flag used by FAKE TLS AUTO ensures the WinDivert driver restarts cleanly with the new rule set, so no system reboot is required when switching between profiles.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →