In short: VPNs in Russia are blocked not by a single IP but automatically — through TSPU (technical means for countering threats) equipment that uses DPI (deep packet inspection). The system looks not only at the server address but at the connection's fingerprint: ports, encryption type, traffic behavior — and recognizes VPN protocols by these signals. By the end of February 2026, Roskomnadzor reported restricting access to roughly 469 services. At the same time, using a VPN itself stays legal: what's restricted is the availability of particular services, not the user's right to privacy.
How Russia blocks VPNs in plain terms
In Russia, VPNs are blocked centrally and automatically: operators' networks carry TSPU equipment (technical means for countering threats) that analyzes passing traffic and restricts connections identified as VPN. Blocking used to come down to banning specific IP addresses and domains, and a service only had to switch addresses. Now the system recognizes the very nature of VPN traffic, so changing the IP helps less and less.
The key tool here is DPI (Deep Packet Inspection). It examines not the content of your messages but the technical signs of a connection and decides whether it looks like a VPN. It's worth separating two different questions that often get mixed up: why a service stops connecting (that's technical availability) and whether using a VPN is legal at all (that's legal status). A detailed look at the legal side is in the article on whether you can use a VPN in Russia.
What is TSPU, and how does DPI fit in?
TSPU is traffic-filtering equipment that, under the "sovereign internet" law, is installed on Russian telecom operators' networks and managed centrally by Roskomnadzor. Most of the country's internet traffic passes through it: as of 2026, TSPU is estimated to cover more than 95% of traffic. This is the equipment that runs the access-restriction mechanisms, including VPN recognition.
DPI is a technology inside TSPU that "looks" into packets more deeply than ordinary routing does. A normal router only sees the destination address, like a postman reading an envelope without opening the letter. DPI, however, analyzes a packet's service attributes: which protocol is used, how the connection begins, which ports are involved. This lets it tell VPN traffic apart from ordinary web browsing, even when it goes to a server that wasn't known in advance.
How DPI recognizes VPN traffic
DPI identifies a VPN by the fingerprints of the connection itself, not by the server address. Even when traffic is encrypted, each protocol has recognizable technical traits — and the system decides based on them. The main signals are:
- The handshake pattern. The way a connection is established looks distinctive for VPN protocols, and DPI can recognize that template.
- Ports and transport. A number of protocols use characteristic ports and UDP by default, which makes them stand out against ordinary HTTPS.
- Entropy and packet size. A fully encrypted stream is statistically different from ordinary traffic in the "randomness" of the data and the distribution of packet sizes.
- Connection behavior. A long, stable tunnel to one address with a steady flow differs from typical browsing, with its many short requests to different sites.
It's important to understand the limit here: DPI recognizes the fact that a VPN is in use and the protocol type, but it does not read the content of the encrypted traffic. What exactly the provider can and cannot see is covered in a separate section below.
Why does Russia block VPNs?
VPNs are restricted because the regulator treats them primarily as a means of accessing blocked resources rather than as a privacy tool. The logic is this: if access to some sites and services is restricted by law, then bypassing those restrictions via a VPN falls under restriction too. Hence both the technical blocking of the services themselves and the separate fines around advertising them.
The legal framework is set by several acts. The "sovereign internet" law (2019) required operators to install TSPU and handed control of filtering to Roskomnadzor. Law No. 281-FZ, in force since 1 September 2025, added fines for advertising a VPN as a means of circumvention and for deliberately searching for extremist materials, including via a VPN. What is and isn't punishable is covered in detail in the articles on fines for using a VPN and the VPN advertising ban law.
How many VPN services are blocked, and which protocols?
The number of restricted services is growing fast: by the end of February 2026, Roskomnadzor reported around 469 restricted VPN services, up from 258 in October 2025 — about a 70% rise in a few months. There is no single public "list of blocked VPNs": these are estimates based on official statements and media reports.
Blocking has shifted from individual services to entire protocols. Since December 2025, additional protocols — not just the addresses of specific services — have increasingly come under restriction. Because of this, a connection can drop regardless of which server is chosen. A summary is in the table.
| What is restricted | How it shows up |
|---|---|
| Individual VPN services | The app stops connecting, servers are unreachable |
| VPN protocols (by traffic fingerprint) | The connection drops regardless of the specific server |
| Advertising and promotion of circumvention | Restricted pages and fines under Article 14.3 of the KoAP |
This is why users increasingly find that a service that worked yesterday won't connect today. From a legal standpoint, this does not make the user an offender — what's restricted is the service's availability, not the right to use it. How the types of VPN and protocols differ is covered in the overview of types of VPN.
"VPN not working" and "VPN banned" are different things
A service being unavailable and a legal ban are not the same, and it's important not to confuse them. "VPN not working" means a specific app or protocol is restricted at the network level and can't establish a connection. "VPN banned" is about legal status, and there is no such ban on using a VPN itself in Russia: there is no article that would penalize connecting to a VPN.
So a situation where a service stops connecting is a matter of technical availability, not a violation on the user's part. How a VPN connection actually works and why it sometimes won't come up is covered in the article on how a VPN works.
Can your provider and DPI see your traffic?
No: with a working VPN, the provider and DPI see the fact of a VPN connection and the volume of traffic, but not its content. The tunnel's encryption hides which sites you open and what you send — only metadata is visible on the outside, namely that an encrypted connection has been made to a certain address. This is the fundamental difference between "recognizing a VPN" and "reading the traffic": DPI does the first, not the second.
The risk of exposure comes not from DPI but from leaks on the device side — for example, a DNS leak, when requests to sites go around the tunnel. So the reliability of protection depends both on the service and on correct configuration. What a VPN does and doesn't protect against is covered in detail in the article on what a VPN protects against.
What this means for the ordinary user
For a law-abiding user, the main point stays the same: a VPN as a privacy and data-protection tool is legal, even if particular services are technically unavailable. Blocks affect the availability of specific apps, not the right to encrypt your traffic, stay safe on open Wi-Fi, or connect to a company's work resources.
When choosing a service under these conditions, a transparent owner and a clear logging policy matter. LiMP VPN is a data-protection service for iOS and Android billed by a Russian legal entity (LLC LiMP): it encrypts traffic and keeps no connection logs. You can see its capabilities in the features section, and the plans on the LiMP VPN pricing page. This material is for reference and educational purposes and is not legal advice; when in doubt, check against the current version of the legislation.
Frequently asked questions
How does Russia block VPNs?
VPNs are blocked centrally and automatically using TSPU equipment with DPI technology on operators' networks. The system analyzes not only the IP address but the connection's fingerprint — ports, encryption type, and traffic behavior — and recognizes and restricts VPN protocols by these signals, even when the server isn't known in advance.
What are TSPU and DPI?
TSPU (technical means for countering threats) is traffic-filtering equipment on operators' networks, managed by Roskomnadzor under the "sovereign internet" law. DPI (deep packet inspection) is the technology inside TSPU that studies the technical signs of a connection and tells VPN traffic apart from ordinary traffic without reading its content.
Why does Russia block VPNs?
Because the regulator treats VPNs primarily as a means of accessing blocked resources. Since access to some sites is restricted by law, bypassing it via a VPN also falls under restriction. The legal basis is set by the "sovereign internet" law and law No. 281-FZ, which added fines around advertising circumvention.
Which VPNs are blocked in Russia?
There is no single public list. Per official statements, by the end of February 2026 access was restricted to roughly 469 VPN services, and the number keeps growing. Blocking increasingly targets protocols rather than specific services, so even a previously working app may become unavailable.
Can my provider see my traffic through a VPN?
No. With a working VPN, the provider and DPI see the fact of a VPN connection and the volume of traffic, but not its content — which sites you open is hidden by encryption. Exposure is possible not because of DPI but because of leaks on the device, such as a DNS leak, so a reliable service and correct setup matter.
Is it legal to use a VPN if it's being blocked?
Yes. Blocking is about the technical availability of services, not about the user's right. There is no article penalizing the act of connecting to a VPN: using a VPN for privacy, data protection, and remote work stays legal.
