# Zyrln: a domain-fronting relay for bypassing DPI-based censorship

> Zyrln is an MIT-licensed relay that routes traffic through Google Apps Script infrastructure to bypass DPI-based censorship, shipped as an Android VPN app and a desktop proxy. Domain fronting can breach a provider's terms and be blocked, so weigh the caveats.

**ajavadinezhad/zyrln** — Domain-fronting relay that routes traffic through Google infrastructure to bypass DPI-based censorship,  Android VPN    app + desktop proxy  https://t.me/z_yrln  | https://t.me/z_yrln_channel

- Repository: https://github.com/ajavadinezhad/zyrln
- Stars: 758 · Forks: 118
- Language: Go
- License: MIT
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/ajavadinezhad-zyrln

## What Zyrln is for

In networks that use deep packet inspection to block circumvention traffic, tools that look like ordinary connections have a better chance of getting through. Zyrln is built on that idea: it is a relay that routes your traffic through Google Apps Script infrastructure so that, to a censor, the connection resembles traffic to Google rather than to a blocked destination, a technique known as domain fronting. It ships as an Android VPN app and a desktop proxy. The audience is people facing DPI-based censorship who want access to the open internet and are willing to set up a relay through Google's infrastructure. It is an anti-censorship tool, so its purpose is reaching blocked content by disguising where traffic is really going. The design centers on borrowing the appearance of a widely-trusted host so that blocking Zyrln would mean blocking Google, which censors are reluctant to do.

## Routing through Google Apps Script

The mechanism is a chain that ends at a relay you control, fronted by Google. The path the README describes runs from your device, through Zyrln, to a Google Apps Script deployment, to your own exit relay, and finally to the real site. The Apps Script layer is what provides the fronting: because the request is made to Google's domain, DPI sees Google, and Apps Script forwards it on. From there your exit relay, on Cloudflare or a VPS, reaches the destination, with authentication keys at each hop so only your traffic uses the relay. The v2 release adds a raw TCP tunnel from Apps Script to a VPS for Android without needing a CA install for normal VPN use. This multi-hop, key-gated design is what lets Zyrln present as Google traffic while still delivering you to arbitrary destinations, which is the essence of a domain-fronting relay.

## Setting up the relay

Zyrln is configured by deploying your own Apps Script and exit relay and pointing the app at them, so setup is more involved than installing a consumer VPN. You configure the Apps Script with your keys and the exit relay URL, for example the script holds values for an auth key and the exit relay endpoint:
```js
const AUTH_KEY        = "your-key-from-step-1";
const EXIT_RELAY_URL  = "https://your-worker.your-subdomain.workers.dev";
const EXIT_TUNNEL_URL = "";
```
You then run the Android app or the desktop proxy pointed at that deployment. The repository is a Go project for the relay side with an Android client, and it provides config export and import to move settings between devices. The first real use is deploying the Apps Script and an exit relay, filling in the keys, and connecting the app to confirm traffic flows through the chain, which validates the fronting path before you rely on it, keeping in mind this is a build-your-own-relay tool rather than a turnkey service.

## Where domain fronting has real limits

The limitations are substantial and worth stating plainly. Domain fronting relies on routing through a provider's infrastructure in a way that provider may not permit, so it can breach Google's or the intermediary's terms of service, and providers have restricted or removed fronting capabilities before, which means the technique can stop working when they change their systems. The README itself notes Zyrln does not defeat IP bans, rate limits, or bot-protection when the underlying connection is already rejected, so it is not a universal bypass. Setup requires deploying and maintaining your own relays, which is real effort and cost. And the legality of circumvention varies by jurisdiction and can carry personal risk for the user. These are not minor caveats: Zyrln is a capable anti-censorship tool, but it depends on a technique that is fragile against provider changes and situated in a legally and operationally sensitive space.

## Zyrln versus other circumvention tools

The alternatives are other anti-censorship systems: protocol-obfuscation tools such as the Xray and V2Ray family, or Tor. Obfuscation tools disguise traffic as innocuous protocols and are widely used against DPI, but they rely on servers whose addresses can be blocked once identified. Tor provides strong anonymity through its network but is often itself blocked and can be slow. Zyrln's difference is the domain-fronting approach: by fronting through Google, it aims to be costly to block because blocking it means blocking Google, at the cost of depending on Google permitting the technique and on you running your own relay. The choice depends on the threat and effort you accept. Use obfuscation tools or Tor for their established ecosystems; consider Zyrln when fronting through a trusted provider is specifically the property you want, understanding its fragility to provider policy and its setup burden.

## MIT license and status

Zyrln is MIT-licensed, so the code is freely reusable, and it is a Go project with an Android client and desktop proxy, reaching a stable v2.0 after several pre-releases. The last push was on 2026-08-13. Approach it as an anti-censorship tool with real caveats: adopt it if you face DPI-based blocking and are willing to deploy and maintain your own Apps Script and exit relay, deploy those components and connect the app to confirm the fronting chain works, and understand that the technique can break when Google changes its systems and does not overcome IP bans or bot protection. Weigh the terms-of-service and legal considerations for your situation before relying on it, since domain fronting sits in a space that is both technically fragile against provider changes and sensitive in policy and law.

## Conclusion

Consider Zyrln if you face DPI-based censorship and want a relay that fronts your traffic through Google Apps Script so it resembles traffic to Google, and you are willing to deploy and maintain your own exit relay. Do not expect it to be turnkey or durable: domain fronting can breach a provider's terms and stop working when they change systems, and it does not defeat IP bans or bot protection. Deploy the Apps Script and exit relay, fill in the keys, confirm the chain works, and weigh the terms-of-service and legal considerations for your situation.

## FAQ

### What is Zyrln?

Zyrln is an MIT-licensed relay that routes traffic through Google Apps Script infrastructure to bypass DPI-based censorship, using domain fronting so connections resemble traffic to Google. It ships as an Android VPN app and a desktop proxy.

### How do I set it up?

You deploy your own Google Apps Script and an exit relay (on Cloudflare or a VPS), configure their keys and URLs, and point the Android app or desktop proxy at that deployment. It is a build-your-own-relay tool rather than a turnkey service.

### What are the main caveats?

Domain fronting can breach the intermediary's terms of service and stop working when the provider changes its systems, and the README notes Zyrln does not defeat IP bans, rate limits or bot protection. Legality of circumvention also varies by jurisdiction.

## Sources

- [ajavadinezhad/zyrln on GitHub](https://github.com/ajavadinezhad/zyrln)
- [Issues](https://github.com/ajavadinezhad/zyrln/issues)
- [License: MIT](https://github.com/ajavadinezhad/zyrln/blob/main/LICENSE)
- [README](https://github.com/ajavadinezhad/zyrln/blob/main/README.md)
- [Releases](https://github.com/ajavadinezhad/zyrln/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ajavadinezhad-zyrln
