ZoogVPN Shadow protocol
Updated 21 September 2026 · How we research
Shadow is one of ZoogVPN's two proprietary transports. It is aimed at networks that do not merely block VPN ports but actively identify and drop VPN traffic.
What we can and cannot tell you
What ZoogVPN says
According to ZoogVPN
Where a transport like this fits
Standard protocols announce themselves. A WireGuard handshake, an OpenVPN header and an IKE negotiation all have recognisable shapes that deep packet inspection can match even when the port is unremarkable. Obfuscated transports exist to remove those signatures, usually by wrapping the tunnel so that it resembles ordinary encrypted web traffic. The general techniques are covered in VPN obfuscation.
Realistic expectations
- Obfuscation costs speed. Extra wrapping and a TCP transport both add overhead, which is consistent with the moderate speed rating ZoogVPN publishes.
- No obfuscation is permanent. Censorship systems adapt, and a transport that works one month may be detected the next.
- Active probing defeats naive designs. Some networks connect to a suspicious server themselves to see how it responds.
- Use it only when you need it. On an ordinary network, WireGuard will be faster and simpler.
Legal note
Alternatives if Shadow is unavailable
ZoogVPN lists Shadow on Windows, macOS, iOS and Android but not on Linux or routers. On those platforms the practical fallback is OpenVPN TCP on port 443 — see OpenVPN TCP vs UDP. On Windows, ZoogTLS is the other proprietary option.
Shadow and ZoogTLS are included with a standard ZoogVPN subscription rather than sold as add-ons.
2-year plans
Affiliate link — we may earn a commission at no extra cost to you. See our affiliate disclosure. Pricing shown as published on VPN Sherlock; confirm current terms at checkout.