Overview
zapret Pocket, ported and maintained by sevcator, brings the renowned zapret Deep Packet Inspection (DPI) circumvention software to rooted Android devices. In jurisdictions where internet service providers (ISPs) and state regulatory bodies employ middleboxes to throttle or block protocols (such as YouTube 4K streams, Discord voice gateways, and social networks), DPI engines inspect the initial TLS ClientHello and SNI (Server Name Indication) fields to drop or delay packets.
zapret Pocket circumvents these middleboxes without requiring a remote VPN or proxy server. Operating entirely on-device via nfqws (Netfilter Queue Web Surrogate) and kernel packet filtering, it desynchronizes packets—sending out-of-order segments, invalid checksums that the destination server drops while confusing the middlebox, and split TLS handshakes that prevent inspection appliances from recognizing prohibited domain names.
Prerequisites & Compatibility
- Root Environment: Compatible with Magisk, KernelSU, and APatch.
- Kernel Requirements: Requires Linux kernel support for Netfilter packet queueing (
CONFIG_NETFILTER_NETLINK_QUEUE/iptablesNFQUEUE). Almost all modern Android stock and custom kernels support these standard networking features out of the box.
There are no documented module conflicts. However, running a system VPN app with a killswitch simultaneously will route traffic through that VPN tunnel before zapret can process outbound packets on raw interfaces.
Packet Desynchronization Mechanics
zapret Pocket deploys nfqws alongside pre-configured desynchronization scripts:
- Fake TLS ClientHello: Precedes the genuine TLS handshake with a crafted fake TLS ClientHello packet. Middleboxes lock onto the dummy domain while the destination server rejects the fake packet and accepts the real connection.
- SNI Splitting (
splitsniext): Fragments the TLS ClientHello right at the Server Name Indication boundary across multiple TCP segments. Middleboxes looking for whole hostnames fail to assemble the stream. - TTL / Hop-Limit Tricks (
ttlpadencap): Sets packet Time-To-Live parameters so that fake packets survive just long enough to fool the inspection middlebox, but expire before reaching the actual destination server. - QUIC / HTTP3 Handshake Manipulation: Modifies UDP QUIC initial headers to unblock YouTube and modern browser connections using HTTP/3.
Configuration & Usage
- Download the latest
zapretmodule zip from the project repository. - Install via Magisk, KernelSU, or APatch.
- Reboot your device.
- The module automatically selects a default general bypass strategy.
- To test or switch strategies, explore the curated scripts in:
Presets include platform-tailored scripts like/data/adb/modules/zapret/zapret/discordfake.sh,discord_voice_badseq.sh,general_alt*.sh, and regional ISP templates. - Execution state and binaries reside in:
/data/adb/modules/zapret/
Troubleshooting & Verification
- DPI Still Blocks Connection: DPI equipment configurations vary significantly across different ISPs and cellular carriers. If the default preset fails to unblock services, switch strategies by selecting an alternative configuration script (e.g. testing
fake-i.sh,splitsniext.sh, orfaketlsalt_*.sh) inside the module directory. - DNS Blocking: zapret desynchronizes TCP and UDP data streams, but does not circumvent DNS poisoning. Ensure you use an encrypted DNS provider (such as DNS-over-HTTPS or DNS-over-TLS) alongside zapret to prevent DNS-level redirection.