Covert Networking
Evade censorship and firewalls with stealth transport protocols that make your VPN traffic look like normal web traffic.
September 30, 2026
Covert Networking disguises tunnel traffic as other types of traffic the network expects to see.
It gives you another way to connect to a network when an ordinary VPN connection is restricted. It won't get around every block, but it addresses a different problem from encryption: getting the connection through in the first place.
1.Features
- Use alternative transports, including HTTPS and WebSocket, when a network restricts ordinary tunnel traffic.
- Disguise the connection's traffic pattern while retaining an encrypted connection.
- Choose another way to reach doxx.net on restrictive networks.
To configure and learn more about your covert networking options navigate to: Account → Settings ⚙ → Privacy → Covert Networking.
2.Alternate Transport Protocols
WebSocket (TCP 443, pinned 4096 bit certificate)
- Makes your connection look like standard HTTPS traffic, with an additional layer of encryption. Supports fast, two-way communication, but packet loss can slow it down. Switching networks, such as from Wi-Fi to cellular, requires a reconnection.
SIP/VoIP (UDP 5060, RTP media stream)
- Makes your connection resemble internet-call traffic. Its low overhead suits real-time communication, and some networks give voice traffic priority. It may be blocked on networks that restrict internet calls.
ICMP Echo (Ping requests/reply tunneling)
- Carries your connection through ping requests and replies, which some restrictive networks still allow. Useful for basic connectivity and messaging, but its lower bandwidth makes it less suitable for heavy browsing. Some router and carrier networks can also cause timing issues.
QUIC (UDP 443, HTTP/3 protocol)
- Makes your connection resemble modern web traffic, with a UDP-based transport designed for performance. Supports keeping the connection when your IP address changes, though this behavior hasn’t been extensively tested and the connection may occasionally stall.
Cloudflare WSS (TCP 443 CDN proxied WebSocket)
- Routes an encrypted WebSocket connection through Cloudflare’s network. Your inner traffic stays encrypted, but Cloudflare can see the source and destination IP addresses. Network changes can also interrupt the connection.
HTTPS (TCP 443, standard web traffic)
- Makes your connection resemble ordinary web browsing.
- Extra Setting: supports routing through an HTTPS proxy. It adds another layer of encryption, but has higher latency and uses more bandwidth than WebSocket.
UDP port selection
- Choose the destination port for direct WireGuard connections. Options
- 51820 (the default), 53, 443, 123 and 5353. This gives you alternatives when a network blocks the usual port.
Cant select port and have custom protocol at same time
3.Common Questions
Will this work through every firewall?
No. Different networks block different types of traffic. Covert Networking gives you alternatives, not a guarantee that every restriction can be bypassed.
Is disguising traffic the same as encrypting it?
No. Encryption protects the contents of your connection. Covert Networking changes how that connection travels and appears to the network carrying it.
Why does my connection drop when I switch from Wi-Fi to cellular?
WebSocket and Cloudflare WSS can disconnect when your network or IP address changes. You’ll need to reconnect. QUIC supports connection migration, but this behavior hasn’t been extensively tested.
Can I connect through an HTTPS proxy?
Yes. Open HTTPS, enable it, then turn on HTTPS Proxy Server. Enter the proxy’s Host and Port, and add a username and password if required. Proxy credentials are stored on your device and aren’t sent to doxx.net. You’ll need to enter them again if you reinstall the app.
Does selecting UDP port 443 turn on HTTPS?
No. The UDP Port setting changes the destination port for direct WireGuard connections. The HTTPS option is a separate transport. Choosing a familiar port doesn’t, by itself, make the traffic use that protocol.
Which port can I try if the default is blocked?
For more restrictive networks such as hotel, airport or corporate networks try 53 or 443 on . Neither is guaranteed to be allowed.