Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

SMTP Tunnel

A SOCKS5 proxy disguised as email traffic to bypass DPI

Details

External ID
46520926
Source
HN
Company
—
Product
SMTP Tunnel
Website domain
github.com
Launched
Jan. 7, 2026
Cohort
—
Upvotes
140
Upvotes percentile
0.9347826086956522
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

A fast SOCKS5 proxy that tunnels your traffic through what looks like normal SMTP email, bypassing Deep Packet Inspection firewalls.How it works: - Client runs a local SOCKS5 proxy (127.0.0.1:1080) - Traffic is sent to server disguised as SMTP (EHLO, STARTTLS, AUTH) - DPI sees legitimate email session, not a VPN/proxyFeatures: - One-liner install on any Linux VPS - Multi-user with per-user secrets and IP whitelists - Auto-generated client packages (just double-click to run) - Auto-reconnect on connection loss - Works with any app that supports SOCKS5Tech: Python/asyncio, TLS 1.2+, HMAC-SHA256 authGitHub: https://github.com/x011/smtp-tunnel-proxy

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
socks5 proxy disguised as email
Manually corrected
False

Could you build this?

Partial Creating a basic SOCKS5 proxy is simple, but reliably obfuscating arbitrary TCP streams inside valid SMTP/STARTTLS traffic to evade active DPI firewalls requires deep low-level networking and protocol evasion skills.

What it would actually take: Needs a dual-ended proxy architecture (client SOCKS5 daemon, remote relay server) implementing a state machine that strictly adheres to RFC 5321 (SMTP) and TLS handshakes while multiplexing bidirectional binary data inside fake MIME bodies or TLS tunnels. The challenging part is avoiding heuristic traffic analysis and stateful DPI resets, which requires deep packet inspection research and low-level socket programming in Go, C, or Rust.

Discussion

20 comments analyzed.

Competitors mentioned: QTGate (IMAP tunnel), dnscat2 (DNS tunneling), Iodine (DNS tunneling), imap-tunnel-proxy

Concerns raised: WebSockets don't sustain large bidirectional traffic for prolonged periods, appears suspicious, DPI can detect non-standard HTTP stream behavior despite encryption, Packet size and timing analysis can leak session information, Port 25 (unauthenticated SMTP) gets flagged by PBL on residential IPs, DNS tunneling over large volumes is obvious to traffic analysis

Feature requests: Support for other common internal services beyond DNS/SMTP for restricted networks, Proper SOCKS-over-SMTP relay tool for internal pentest scenarios, Packet padding/delays to mimic fixed-rate protocols and evade detection

Competitors

Other products that read as similar to this one — 193 launches clear the similarity bar, closest 8 shown.

Attention rank: #9 of 194 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 70 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.