# EasySNI ships as v2rayez: one Go binary behind a panel on port 8765

> The EasySNI repository builds a single executable called v2rayez, a local web panel holding an SNI spoofing tunnel, xray and sing-box engines, a config library, scanners and a client-side domain fronting proxy. The panel binds 0.0.0.0 by default and MITM TLS when you trust its CA.

**macan-dev/EasySNI** — Bypass censorships using Go Lang

- Repository: https://github.com/macan-dev/EasySNI
- Website: https://telegram.me/EzAccess1
- Stars: 444 · Forks: 82
- Language: Go
- License: MIT
- Published: 2026-09-20 · Updated: 2026-09-20 · Language: en
- Canonical page: https://hysenlabs.com/projects/macan-dev-easysni

## The repository is EasySNI, the binary is v2rayez

The naming does not match, and knowing that up front saves confusion. The repository is macan-dev/EasySNI, the Go module inside `go.mod` is named `ezsni`, the configuration file is `ezsni-config.json`, and the executable every command, build script and release refers to is `v2rayez`.

What that binary is: a single-file local web control panel for working around DPI filtering and reaching CDN-fronted proxies. You run one executable, a dashboard opens in your browser or in its own app window, and the SNI tunnel, the xray and sing-box engines, the scanners, the config library, the Google-fronted relay and the client-side domain fronting proxy all sit behind that one page. No installer, no background services, no telemetry.

It is Go with an embedded UI, so the whole application is one portable file. The README carries an English and a Persian version, and the interface switches between them.

Releases are frequent and small: v4.5.1 on 2026-05-31, v4.6.5 on 2026-06-03 and v4.7.5 on 2026-06-12, with the last push on 2026-06-21. It is MIT licensed, and the page states up front that it is provided as is with no warranty and is intended for education, testing and research.

## The xray and sing-box engines are downloaded, not compiled in

The `go.mod` file is short in a way that explains the architecture. The module is `ezsni`, it declares Go 1.22, and its only direct dependency is `github.com/skip2/go-qrcode`, which is the QR sharing feature in the config library.

Everything heavy is fetched at runtime. The XRay Core tab detects and downloads xray and sing-box, then runs any config through the chosen engine as a local SOCKS5 proxy or as a system-wide TUN VPN, with start and stop, a TUN toggle, and Set and Clear system proxy in the header.

That design has consequences. The binary stays small and portable, and you are not shipping someone else's VPN core inside your build. In exchange, the first run needs to download an engine, and what you get is whatever the downloader resolves to at that moment.

The config library is where the time goes. You make groups, add configs by pasting `vless://`, `vmess://`, `trojan://` or `ss://` links, dragging in a `.txt`, importing a subscription URL, loading the built-in SNI and spoof list, or fetching the latest. The structured editor exposes address, port, UUID or password, cipher, transport, path, host header, security, SNI, fingerprint, ALPN and Reality keys, with a live preview, and everything is auto-saved.

## The SNI tunnel writes a lie into the handshake and keeps the real endpoint

The mechanism is worth understanding because it explains both what the tool does and what it cannot do.

Most basic DPI filtering works by reading the SNI sent in the clear during the TLS handshake. The tunnel connects to the real server but writes a permitted hostname into that field, so the filter sees a domain you are allowed to reach while your real session continues to the endpoint you asked for.

On top of that sit the desync options: fragmentation, fake packets and uTLS fingerprints. Those exist because a filter that only reads SNI is easy to satisfy, while a filter that also looks at packet size and timing needs the handshake to look like something else.

The scanners exist to find out which SNI works from where you are. There is an SNI scan, a Mass SNI mode, a Clean IP Scanner, a CDN edge test, a CDN configs builder, a Mass URI tester, and a site scanner with live progress that tries Cloudflare first.

One note on naming that matters when you read the tree: `v2rayez-saved-sni.json` and the built-in SNI and spoof list are the state behind that whole path, saved next to the binary so the working set survives a restart.

## Domain fronting is a local MITM proxy, and that is the cost of it

The Domain Fronting tab goes further than SNI spoofing for sites behind a CDN. A local MITM proxy reads each request's real Host, resolves it through fronted DNS over HTTPS so poisoned answers are never used, then reaches the CDN edge behind an allowed front SNI. The network sees ordinary traffic to the front domain.

The rules file is one per line, either `host-suffix = front-SNI` or `host-suffix = front-SNI = dial-host` when the TCP connection also has to be redirected, which some CDNs require. With no dial host it connects to the real IP and only swaps the SNI. A built-in rule set ships ready to use. Leaving the default front blank means unmatched hosts pass straight through with no interception at all.

DNS is handled with presets for Cloudflare, Google and Quad9, or your own server, resolved over the front so a blackhole answer such as a `10.10.34.x` address is never used.

The cost is that the proxy has to read your HTTPS, so you download and trust a CA certificate in `.pem` or `.crt` form. The project states the private key never leaves your machine.

The limit is stated too: fronting only helps sites already on a CDN that tolerates a mismatched SNI and Host, and it defeats SNI-based blocking, not destination-IP blocking.

## Build tags must come before the dot, and the README says so twice

Optional transports are behind build tags, and the ordering rule is called out because getting it wrong produces a confusing error:

```bash
go build -tags "psiphon livekit" .        # correct
# go build . -tags psiphon                 # WRONG: "malformed import path -tags"
```

Tagged builds also fetch their dependencies first, from `go get github.com/Psiphon-Labs/psiphon-tunnel-core/ClientLibrary/clientlib@latest` and a second module whose path is cut off in the visible page.

Building from source needs Go 1.22 or newer:

```bash
git clone <your-fork-url> v2rayez
cd v2rayez
go build -o v2rayez .
./v2rayez
```

Cross-compilation is three environment variable pairs, for Windows on amd64, macOS on arm64 and Linux on amd64. There are also convenience scripts: `build-all.bat` on Windows is interactive and lets you pick a tag profile of Standard, Psiphon, LiveKit or All, fetching the right dependencies and building, while `./build-all.sh` does the standard profile on macOS and Linux and `./build-all.sh psiphon` takes a tag and fetches its dependencies itself.

## The panel listens on every interface unless you tell it not to

The quick start is two commands:

```bash
./v2rayez            # Linux / macOS
v2rayez.exe          # Windows
```

It listens on `0.0.0.0:8765` by default and opens the dashboard; if it does not, the fallback is `http://127.0.0.1:8765`. The flags are few and their defaults matter:

| Flag | Default | Meaning |
| --- | --- | --- |
| `-addr` | `0.0.0.0:8765` | Address the panel listens on |
| `-open` | `true` | Open the dashboard on start |
| `-window` | `true` | Use a dedicated app window if available |
| `-minimize` | `true` | Minimize the console window on Windows |

Binding to all interfaces is a convenience for people running the panel on a second machine, and a problem for everyone else, because a control panel that manages proxies, subscription URLs and system proxy settings should not be reachable from the office network by default. The loopback-only invocation is in the README:

```bash
./v2rayez -addr 127.0.0.1:8765 -open=false -window=false   # local only
```

Nothing in the documentation tells you to do this, which is worth knowing before you run it on a shared network.

## WinDivert drivers ship in the repository, and PSIPHON.md is separate

The tree explains how far this goes. Alongside the Go sources, `main.go`, `internal/`, `go.mod` and `go.sum`, there are `WinDivert.dll` and `WinDivert64.sys` committed as binaries, which are the Windows packet interception driver and its system component. That is what the Extras tab manages, and it is a driver install rather than a library call, so it needs administrative rights and a reboot more often than anyone expects.

There is a separate `PSIPHON.md` covering the Psiphon tunnel, which is also behind an optional build tag, and an Extras section that lists a Cloudflare Worker maker plus Psiphon and SPlus tunnels.

The Google Tunnel is the other unusual piece. It is a domain-fronted relay through a Google Apps Script and a Cloudflare Worker that you deploy yourself, and both scripts are generated inside the app, so there is no external repository to trust or clone.

Other files explain themselves: `Configs/` holds configurations, `ezsni-config.json` and `v2rayez-saved-sni.json` are the app's saved state, `scanner.html` is the site scanner surface, `versioninfo.json` feeds the Windows build, `repo/` and `docs/` hold documentation, and `telegram-post.md` is the announcement copy.

The homepage is a Telegram channel rather than a website, which tells you where support and updates live.

## Conclusion

Adopt EasySNI if you need SNI camouflage and CDN fronting from one portable file with no installer and no installer-managed service, and keep in mind you are taking on both an interception CA and a panel that listens on every interface by default. Before you run it, change two things. Bind the panel to loopback with `-addr 127.0.0.1:8765 -open=false -window=false`, because the shipped default of `0.0.0.0:8765` is reachable from your local network. And decide whether you are going to trust the CA the domain fronting proxy generates, since that is what lets it read your HTTPS locally, and the private key stays on your machine only if you keep it there. Then read the boundary the project states itself: fronting helps only sites on a CDN that tolerates a mismatched SNI and Host, and it defeats SNI-based blocking, not destination-IP blocking. Also note the project is provided as is with no warranty and asks you to follow local law and the terms of the services you point it at.

## FAQ

### What does EasySNI do?

It builds as one Go executable named v2rayez that opens a local web panel on port 8765 containing an SNI spoofing tunnel, downloaded xray and sing-box engines, a config library, several scanners, a Google Tunnel relay and a client-side domain fronting proxy. There is no installer and no background service.

### How does the SNI tunnel in EasySNI work?

Most DPI filters read the SNI sent in clear during the TLS handshake. The tunnel connects to the real endpoint while writing a permitted hostname into that field, with optional desync through fragmentation, fake packets and uTLS fingerprints for filters that look at more than the hostname.

### When does domain fronting not help in EasySNI?

It only works for sites already on a CDN that tolerates a mismatched SNI and Host, and it defeats SNI-based blocking rather than destination-IP blocking. With the default front left blank, unmatched hosts pass through directly with no interception.

### How do I build EasySNI from source?

You need Go 1.22 or newer, then clone into a directory named v2rayez, change into it and run `go build -o v2rayez .`. Optional transports are behind build tags and the flags must come before the dot, because putting them after fails with a malformed import path error.

### Can I keep the EasySNI panel off my local network?

Yes. The panel listens on 0.0.0.0:8765 by default, and running `./v2rayez -addr 127.0.0.1:8765 -open=false -window=false` binds it to loopback only, skips the dashboard launch and skips the dedicated app window.

## Sources

- [License: MIT](https://github.com/macan-dev/EasySNI/blob/main/LICENSE)
- [macan-dev/EasySNI on GitHub](https://github.com/macan-dev/EasySNI)
- [Project website](https://telegram.me/EzAccess1)
- [README](https://github.com/macan-dev/EasySNI/blob/main/README.md)
- [Releases](https://github.com/macan-dev/EasySNI/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/macan-dev-easysni
