TROJAN
About TROJAN
Trojan disguises proxy traffic as normal HTTPS: the client performs a standard TLS handshake with a certificate that looks like any website's, then authenticates with a password inside the encrypted channel. There is no recognizable handshake fingerprint, which was its original advantage against protocol detection. Trojan supports TLS, WebSocket and gRPC transports and accepts SNI camouflage hosts. Because it always expects TLS, plain-text Trojan links do not exist in practice.
Top countries
Counts reflect the country codes observed on TROJAN records. Follow a row to the protocol-country combination.
Frequently asked questions
What is Trojan?
Trojan is a proxy protocol that disguises traffic as ordinary HTTPS. A record contains a password, a server address and TLS settings such as SNI.
What does freshness mean for Trojan records?
Freshness is when a record was last observed in a public source. It is not an availability check — a fresh record can still be offline.
How are Trojan records deduplicated?
Records with the same protocol, address, port and credentials are merged, and their source observations are combined into one history.
Freshness shows when a config was last seen in a public source — not whether it works.