5G Proxy Client
Routes device traffic through a remote SOCKS5 proxy via TUN. No root, TCP/UDP.
tokyoxpa3 VPN & Proxy
Screenshots
Description
Android SOCKS5 TUN tunnel client — routes the device's entire network traffic through a remote SOCKS5 server using a TUN virtual interface. No root required.
Features:
- User-space TCP state machine forwarded via SOCKS5 CONNECT
- UDP / DNS / QUIC relay via SOCKS5 UDP ASSOCIATE (UDP-in-UDP or UDP-in-TCP 0x04)
- Remote DNS (fakedns) with fake IPv4 (198.18.0.0/15) and fake IPv6
- IPv4 + IPv6 dual-stack support
- Per-App routing modes: Global, Allowlist, or Exclusion
- Auto-reconnect with exponential backoff on connection drop
- Live traffic statistics (up/down bytes & session count) in persistent notification
- Custom primary & secondary DNS servers
- Start tunnel on boot
- Quick Settings tile for one-tap tunnel toggle
- Multiple profile management with JSON export/import via clipboard
- Native C (epoll) engine + JNI + Kotlin UI
Privacy notes:
- While the tunnel is up, the proxy server's hostname is re-resolved outside the tunnel (needed to follow DDNS / IP changes without tearing the TUN interface down). That lookup is sent to the DNS servers of the network the tunnel actually runs over. The custom DNS servers above are used only as a fallback when that resolver gives no answer, and the fallback is written to the log.
- With Remote DNS enabled, DNS queries from apps are relayed to the proxy exit instead of being answered locally.
Open source (MIT), reproducible builds.
What’s new (1.6.5)
- Fix: after a network change, the DNS servers used to re-resolve the proxy server's hostname were the tunnel's own advertised servers (8.8.8.8 / 1.1.1.1 by default), not the DNS of the network the tunnel actually runs over. The intended "fall back to the local network's DHCP DNS" step had never taken effect, because it read the active network — which, for a VPN app, is its own VPN network. The underlying network's resolver is now tried first, so the hostname is not handed to a third-party resol
Versions
Permissions
What the app asks the system for. Android only grants sensitive access after you confirm it.
- Internet accessSend and receive data over the internet.
- Network stateCheck whether and how the device is connected.
- Foreground serviceKeep running in the background, visible in the status bar.
- FOREGROUND_SERVICE_SPECIAL_USE
- NotificationsShow notifications.
- Installed appsSee which apps are installed.
- Run at startupStart automatically after the device is switched on.
- USE_FULL_SCREEN_INTENT
Show 3 more permissions
- REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
- BIND_QUICK_SETTINGS_TILE
- socksclient.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Comments