VPN on mobile data: why it works at home and dies on the carrier
Mobile carrier whitelists: what they are, why a VPN works on Wi-Fi and fails on mobile data, and which connection type passes through Russian mobile carriers.
"On Wi-Fi it flies, on mobile data it won't connect" is the most recognisable complaint of 2026. Your home ISP and your mobile carrier filter traffic differently, and what passes one gets cut by the other. Here is the mechanism and what to do about it.
What whitelists are
Ordinary blocking bans specific addresses and lets everything else through. A whitelist does the opposite: it lets through only what clearly looks allowed and cuts everything unrecognised. During "tightening" periods carriers switch mobile networks into this mode: popular sites, messengers, banks and app stores pass, any unusual connection is dropped. A VPN on a non-standard port or with an unusual handshake is exactly "unusual".
Home ISPs rarely do this: different equipment, different rules. Hence the difference between Wi-Fi and mobile on the same phone.
What passes whitelists
Only what looks like loading an ordinary page: HTTPS on port 443, to a known address, with ordinary-looking requests. Surok has a dedicated profile for this, "Europe · auto": the connection goes to a content delivery network used by thousands of sites and looks like image downloads inside. The carrier can't shut a CDN without breaking half the internet, so it passes.
Reality profiles on 443 often pass too: from outside it is ordinary HTTPS to a known site. Profiles on non-standard ports like 2053 or 8443 are the first to go under the knife. They stay for home networks, where they are faster.
How to confirm it is this
- Turn Wi-Fi off, leave mobile data only.
- Connect with a regular profile: a timeout where Wi-Fi worked confirms the diagnosis.
- Switch to "Europe · auto" and try again.
Our app does this itself: on mobile it starts with the CDN profile, on Wi-Fi with the fast direct one.
Carrier specifics
We don't publish a "what works where" table: it changes week to week and region to region, and any such table is wrong within days. What is stable: big carriers switch whitelisting on in waves, often per region, and the CDN profile has passed everywhere we've checked. If even that fails for you, message support with your carrier and city: we look at what reaches the server, and such reports help us change routes in advance.
Why not just "make it faster"
The CDN profile is slower than direct: every request makes an extra hop through the delivery network. For sites, messengers and standard-quality video that is enough; for big downloads the direct profile is better. That is why the app doesn't keep you on the CDN permanently and returns to the direct profile when the network allows.
In short
Mobile carriers switch on whitelists, home ISPs don't. Only connections that look like ordinary websites pass whitelists. Surok has a CDN profile for exactly that, and on mobile that is the one to pick. The app picks it itself; in third-party clients switch manually.
