MITM-DomainFronting: a local certificate trick that reaches YouTube, Instagram and WhatsApp without a server
Receiving unencrypted data with MITM, Then send it with DomainFronting
At a glance
- What is it?
- patterniha/MITM-DomainFronting uses a locally trusted certificate to intercept plaintext browser traffic and then re-send it through Xray with a forged SNI. It is a narrow tool for a handful of services, not a general VPN replacement.
- Who is it for?
- Adopt MITM-DomainFronting only if you want direct browser access to the specific services the README lists (YouTube, Instagram, WhatsApp, Facebook, Reddit and some Fastly-hosted sites) and you accept that it is not a full tunnel. Do not adopt it if you need system-wide coverage for native apps, or if you cannot manage a self-signed root certificate on every device.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 66 days ago.
- What is it written in?
- Mainly Batchfile, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The gap MITM-DomainFronting fills, and the one it leaves open
The README opens with a disclaimer that is unusual for a circumvention project: the method is not meant to bring your config online or to provide full internet access. It is meant to make some specific services reachable directly, without a server and without a Cloudflare worker. As of the date given in the README (1405/3/10 in the Persian calendar), that list is YouTube, Instagram, WhatsApp, Facebook, Reddit, and some sites behind Fastly. The author states that other services will be added as they become reachable.
The audience is therefore narrow. If your problem is "I cannot open YouTube or Instagram in a browser," this is aimed at you. If your problem is "my whole machine needs a tunnel," it is not. The README repeats this boundary twice, once in the opening paragraph and again in the Android section, where it notes that on non-rooted Android the method works only inside browsers and that standalone apps generally do not support it. That means Google Meet or Google Drive have to be used through a browser rather than their apps.
How the plaintext interception and fake SNI actually fit together
The name describes the two halves of the mechanism. First, the tool impersonates the identity of the destination server so that the browser hands over data that is not encrypted. Second, it sends that data onward with a forged SNI. The README states this directly: the method first forges the identity of the main server to receive unencrypted data from the browser, then sends it to the real server with a fake SNI.
That first half is why a personal certificate is mandatory. The browser only surrenders plaintext if it trusts the certificate presented to it, which is why the setup installs mycert.crt as a trusted root certificate on the operating system or in a single browser. The second half is where Xray takes over: the project began as a separate Python implementation in the author's MMDF repository, and the README says it was later added to Xray-core through work tracked in issue 4348. The practical consequence is that you no longer need the original standalone code; a v2ray config using the Xray core is enough.
The repository layout matches that story. The top level holds only .gitignore, LICENSE, README.md and an Xray-config directory, which is where MITM-DomainFronting.json lives. There is no server component to deploy, which is the whole point of the design.
Windows setup: certificate_generator.bat, v2rayN and an empty socks port
The README's Windows path starts with v2rayN. Download the latest v2rayN-windows-64.zip from the v2rayN releases page and extract it.
The next step is generating your own certificate. Move certificate_generator.bat into the v2rayN-windows-64\bin folder and run it there. After a short wait, two files appear: mycert.crt and mycert.key. The README warns in bold that you must use your own certificate, never someone else's crt, and never share your key.
Then the crt has to be trusted. On Windows, right-click mycert.crt, choose install certificate, select local machine, then "place all certificates in the following store" and pick Trusted Root Certification Authorities. The README also gives the equivalent Chrome route through Settings, Privacy and security, Security, Manage certificates.
With the certificate trusted, run v2rayN, click "add a custom configuration" under configuration, give it any name, and import MITM-DomainFronting.json. Set core type to xray and leave the socks port empty. The README is explicit that the socks port must be left blank. Finally select the config and choose set system proxy. From that point on, the method is a simple on/off toggle, as the README describes it.
The README does not publish the JSON contents. What it names are the file MITM-DomainFronting.json in the Xray-config directory, the core type xray, and the empty socks port field, so read the config in the repository rather than reconstructing it.
Android without root: asset files, a CA install, and a Firefox-only extra step
The Android instructions use v2rayNG. Install it from the v2rayNG releases page. For the certificate you have two options: copy the mycert.crt and mycert.key you already generated on Windows, or generate a self-signed pair through the Regery tool the README links to, renaming the downloads to mycert.crt and mycert.key.
In v2rayNG, add both files under Asset files. Then install the crt as a trusted root: Settings, Security and privacy, More security settings, Install from device storage, CA Certificate, Install anyway, and pick mycert.crt. If it worked, the certificate appears under View security certificates, in the User tab. The README cautions that these menus differ between phones.
Import MITM-DomainFronting.json through "import from locally" and run it. Two settings matter: Enable Hev TUN FEATURE must be on, and the default port 10808 must not be changed. The README spells the TUN option as "Enable Hev TUN FEATURE".
Chromium-based browsers then work as-is. Firefox needs one more toggle, reached by tapping the Firefox logo five times in About Firefox, then Settings, Secret Settings, and "Use third party CA certificates".
What it will not do, and where the design gets uncomfortable
The clearest limitation is already in the README: on non-rooted Android, standalone apps generally cannot use the method, only browsers. That rules out most of the apps people actually want a tunnel for. The README's own workaround is to open Google Meet or Google Drive in a browser instead.
The second limitation is the trust model. Installing a root certificate means anything signed by that key is accepted by the system or browser. The README's warning is blunt: do not take a crt from anyone, do not give your key to anyone, create and use your own. That is not boilerplate. A shared certificate would let whoever holds the matching key impersonate sites to your browser.
The third is scope. The README does not claim the method keeps a config alive or delivers full internet access, and it does not document a rollback path for removing the trusted root once installed. If you install the certificate at the local machine store level, undoing that is a manual certificate-store operation, and the README does not walk through it. Treat the certificate installation as the step with the least documentation and the most lasting effect.
Finally, the project is written primarily in Batchfile, which tells you where the author's testing effort went. Windows and Android get detailed walkthroughs; Linux and macOS are listed as supported in the opening line but the README provides no separate instructions for them.
MITM-DomainFronting versus a plain v2ray or Xray client
The obvious alternative is an ordinary Xray or v2ray configuration pointed at a server you control, or a full VPN client. The difference is architectural, not cosmetic. A normal proxy config requires a remote endpoint that terminates the connection, and every byte travels through it. MITM-DomainFronting has no server of its own: it relies on the target service accepting a connection whose SNI does not match the real destination, which is why the README says no server and no worker are needed.
That trade buys reachability for a short list of hosts and costs you everything else. A conventional client covers all traffic and all apps; this covers the services the README names, and on Android only inside browsers. If your requirement is a general tunnel, a hosted config is the better fit even though it costs a server. If your requirement is browser access to a handful of blocked sites with no infrastructure at all, the fronting approach is the one that matches.
The README also points to the Xray-core issue thread where the technique was merged, which is the place to look if you want to understand how the upstream implementation differs from the original Python code in MMDF.
Maintenance, versioning and the GPL-3.0 licence
The repository is not archived, and its last push was on 2026-07-28. Releases are frequent and numbered rather than semantic: v21 on 2026-05-23, v22 on 2026-05-30, v23 on 2026-06-01. The gap between v21 and v22 is seven days, which suggests small incremental changes rather than a stable release cadence. Upgrading means re-importing a config into v2rayN or v2rayNG; the README does not describe a migration path between versions, so keep your own copy of MITM-DomainFronting.json before replacing it.
The project is licensed GPL-3.0. If you redistribute it or build on it, the copyleft terms of that licence apply to derivative works. That is a statement about the licence text, not legal advice; if you plan to ship it inside a product, read the LICENSE file in the repository and get proper counsel.
The README ends with USDT donation addresses on BEP20 and TRC20 and a Telegram handle, which is the author's stated support channel. There is no homepage field on the repository, so the README itself is the documentation.
Editorial conclusion
Adopt MITM-DomainFronting only if you want direct browser access to the specific services the README lists (YouTube, Instagram, WhatsApp, Facebook, Reddit and some Fastly-hosted sites) and you accept that it is not a full tunnel. Do not adopt it if you need system-wide coverage for native apps, or if you cannot manage a self-signed root certificate on every device. Before anything else, verify that the certificate_generator.bat output (mycert.crt and mycert.key) installs as a trusted root on your platform and that v2rayN shows core type xray with the socks port field empty, because the README treats that empty field as a requirement, not a preference.
Frequently asked questions
Does MITM-DomainFronting give me full internet access?
No. The README states plainly that the method is not meant to bring your config online or provide full internet access; it makes certain specific services reachable directly. The listed services are YouTube, Instagram, WhatsApp, Facebook, Reddit and some Fastly-hosted sites.
Why does MITM-DomainFronting need a personal certificate?
The method first forges the identity of the destination server so the browser hands over unencrypted data, which only works if the browser trusts the certificate. That is why mycert.crt must be installed as a trusted root certificate on the system or in a specific browser.
Can I use MITM-DomainFronting in apps on a non-rooted Android phone?
Generally no. The README says that on non-rooted Android the method works only through browsers, and standalone apps usually do not support it. For Google Meet or Google Drive, the README's own suggestion is to use a browser instead of the app.
Which port and core type should I set for the MITM-DomainFronting config?
In v2rayN, set core type to xray and leave the socks port empty, as the README requires. On Android with v2rayNG, do not change the default port 10808 and make sure Enable Hev TUN FEATURE is on.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/patterniha-mitm-domainfronting)