Conditions behind the Great Firewall change without notice. Every figure here is dated — check how we verify before you rely on it.
Intelligence methodology 2026 GFW Intelligence Briefing

The Physics of Verification

The Great Firewall of 2026 is an AI-driven adversary. We analyze Entropy Analysis, Active Probing triggers, and packet timing signatures to separate marketing myths from operational reality.

Regulatory Alert: The Cybercrime Prevention and Control Law (draft Feb 2) introduces 3-year exit bans. Our methodology now factors regulatory risk alongside technical performance. Read our risk assessment →

Intelligence Pillars

The three foundational metrics we use to verify bypass capability.

Protocol Analysis

We assess which protocols a service actually offers, and whether that design is known to resist active probing and deep packet inspection. This is documentation and protocol analysis, not packet capture from inside China.

Obfuscation Over Encryption

Obfuscation matters more than encryption strength here. Traffic that looks like ordinary HTTPS survives where high-entropy tunnels get dropped, so we weight services by whether they offer credible mimicry at all.

Terms and Infrastructure

We look at the surrounding terms: routing quality, refund window, jurisdiction and app support. A 30-day refund is worth more to a traveller than a marginal speed claim, because it lets you test risk-free.

The Scoring Engine

How we weigh technical metrics to arrive at a reliability score.

Criteria Weight Technical Focus
Bypass reliability 40% How consistently it connects from mainland China. A VPN that does not connect is worth nothing at any price, so this dominates.
Obfuscation strength 20% Whether the service offers credible traffic mimicry rather than a bare tunnel. This determines how long it keeps working after a crackdown.
Value for money 15% Price against what you actually get. Weighted below reliability because the failure mode of a cheap VPN in China is total.
Refund terms 10% How much risk you carry if it does not work for you. A 30-day window lets you test properly; 7 days often will not survive a disruption cycle.
App quality 10% Setup difficulty and daily usability, which matters more to a short-trip traveller than to a technical resident.
Support and transparency 5% Whether help is reachable when you are behind the firewall and the provider website is blocked.

Every score, worked out

Each rating below is our editorial judgement on a 0–10 scale. The total is not a separate opinion — it is the weighted sum of those ratings, using the weights above, applied identically to every service. Add the row up yourself if you like; that is the point of publishing it.

We rebalanced these weights in August 2026. Previously value and refund terms carried 40% between them, which meant the cheapest service won regardless of whether it connected — the opposite of what matters behind the Great Firewall. Bypass reliability and obfuscation now carry 60%. Several rankings changed as a result, including our former top pick.

Service Bypass reliability 40% Obfuscation strength 20% Value for money 15% Refund terms 10% App quality 10% Support and transparency 5% Total
ExpressVPN 7 2.80 7 1.40 8 1.20 9 0.90 9 0.90 8 0.40 7.6
Astrill VPN 9 3.60 9 1.80 3 0.45 3 0.30 6 0.60 7 0.35 7.1
Surfshark 6 2.40 6 1.20 9 1.35 9 0.90 8 0.80 7 0.35 7.0
TorGuard 7 2.80 8 1.60 6 0.90 4 0.40 5 0.50 6 0.30 6.5
PrivateVPN 5 2.00 5 1.00 8 1.20 9 0.90 5 0.50 5 0.25 5.9
LetsVPN 7 2.80 5 1.00 6 0.90 3 0.30 6 0.60 3 0.15 5.8
NordVPN below 5.5 — avoid 3 1.20 4 0.80 7 1.05 9 0.90 9 0.90 8 0.40 5.3
ProtonVPN below 5.5 — avoid 3 1.20 5 1.00 6 0.90 8 0.80 8 0.80 7 0.35 5.1
Veee below 5.5 — avoid 6 2.40 5 1.00 6 0.90 1 0.10 5 0.50 2 0.10 5.0
Private Internet Access below 5.5 — avoid 2 0.80 3 0.60 8 1.20 9 0.90 7 0.70 6 0.30 4.5
CyberGhost below 5.5 — avoid 2 0.80 2 0.40 7 1.05 9 0.90 7 0.70 6 0.30 4.2

Each cell shows our rating, then its weighted contribution. We publish no success percentages, because we do not operate test infrastructure inside China and will not present judgement as measurement. Disagree with a rating? Tell us which one and why — that is a far more useful argument than disputing a total.

Technical Lexicon

Definitions for 2026-era Great Firewall evasion techniques.

VLESS Stateless Protocol
A lightweight transport protocol designed to eliminate the handshake signature found in legacy methods, making it resistant to Deep Packet Inspection (DPI) active probing.
XTLS-Reality
A mechanism that forwards client requests to a legitimate website, using their real TLS certificates to steal their identity and defeat AI-based entropy analysis.
JA4 Fingerprinting
A protocol-specific fingerprinting method that analyzes Client Hello packets. We recommend VPNs that randomize these to avoid being classified as "Proxy Traffic."
CN2 GIA Routing
The highest quality transit line offered by China Telecom. Essential for ensuring minimal packet loss during peak usage hours (8PM - 11PM).

Conflict of interest — updated August 2026

This site is funded by affiliate commissions, and we may earn one when you follow a link from here. That is the conflict, stated plainly.

What we do about it: scores are computed from the weights published above, applied identically to every service, with the full arithmetic printed on this page. A commercial relationship cannot move a score without moving a sub-score, and a sub-score cannot move without a written reason. If our reasoning looks wrong to you, the working is right there to argue with.

Worth knowing: some services here pay us and some do not, and that is not what decides the order. Our highest-rated service for outright reliability is also one of the most expensive, and we say so on its card rather than steering you toward a cheaper option that happens to suit us better.

GFW Intelligence Team Protocol Analyst Editorially reviewed

Specializing in entropy detection analysis, active probing verification, and CN2 GIA routing performance measurement since 2021.