SMTP Tunnel
A SOCKS5 proxy disguised as email traffic to bypass DPI
Details
- External ID
- 46520926
- Source
- HN
- Company
- —
- Product
- SMTP Tunnel
- Website domain
- github.com
- Launched
- Jan. 7, 2026
- Cohort
- —
- Upvotes
- 140
- Upvotes percentile
- 0.9347826086956522
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
A fast SOCKS5 proxy that tunnels your traffic through what looks like normal SMTP email, bypassing Deep Packet Inspection firewalls.How it works: - Client runs a local SOCKS5 proxy (127.0.0.1:1080) - Traffic is sent to server disguised as SMTP (EHLO, STARTTLS, AUTH) - DPI sees legitimate email session, not a VPN/proxyFeatures: - One-liner install on any Linux VPS - Multi-user with per-user secrets and IP whitelists - Auto-generated client packages (just double-click to run) - Auto-reconnect on connection loss - Works with any app that supports SOCKS5Tech: Python/asyncio, TLS 1.2+, HMAC-SHA256 authGitHub: https://github.com/x011/smtp-tunnel-proxy
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- socks5 proxy disguised as email
- Manually corrected
- False
Could you build this?
Partial Creating a basic SOCKS5 proxy is simple, but reliably obfuscating arbitrary TCP streams inside valid SMTP/STARTTLS traffic to evade active DPI firewalls requires deep low-level networking and protocol evasion skills.
What it would actually take: Needs a dual-ended proxy architecture (client SOCKS5 daemon, remote relay server) implementing a state machine that strictly adheres to RFC 5321 (SMTP) and TLS handshakes while multiplexing bidirectional binary data inside fake MIME bodies or TLS tunnels. The challenging part is avoiding heuristic traffic analysis and stateful DPI resets, which requires deep packet inspection research and low-level socket programming in Go, C, or Rust.
Discussion
20 comments analyzed.
Competitors mentioned: QTGate (IMAP tunnel), dnscat2 (DNS tunneling), Iodine (DNS tunneling), imap-tunnel-proxy
Concerns raised: WebSockets don't sustain large bidirectional traffic for prolonged periods, appears suspicious, DPI can detect non-standard HTTP stream behavior despite encryption, Packet size and timing analysis can leak session information, Port 25 (unauthenticated SMTP) gets flagged by PBL on residential IPs, DNS tunneling over large volumes is obvious to traffic analysis
Feature requests: Support for other common internal services beyond DNS/SMTP for restricted networks, Proper SOCKS-over-SMTP relay tool for internal pentest scenarios, Packet padding/delays to mimic fixed-rate protocols and evade detection
Competitors
Other products that read as similar to this one — 193 launches clear the similarity bar, closest 8 shown.
Attention rank: #9 of 194 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 70 days after the earliest competitor.
- ReSocks · ph · 2026-09-11 · 2 upvotes · similarity 0.54
- cdn-tunnel · github · 2026-09-16 · 9 upvotes · similarity 0.52
- Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting · hn · 2025-12-25 · 86 upvotes · similarity 0.52
- Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard) · hn · 2025-11-27 · 19 upvotes · similarity 0.48
- Netrinos · hn · 2025-12-19 · 93 upvotes · similarity 0.48
- Tether Link Utility · ph · 2026-09-10 · 2 upvotes · similarity 0.46
- Mtproto.zig · hn · 2026-04-03 · 24 upvotes · similarity 0.46
- VaultSandbox · hn · 2026-01-06 · 58 upvotes · similarity 0.45
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.