Frequently asked questions
Click a question to expand it. Coming from a ? on your dashboard opens the matching answer automatically.
How SmokeVPN works
SmokeVPN routes your traffic out through a pool of servers around the world, so the sites you visit see one of our servers - not you. One account covers all your devices, plus two always-on proxies.
We're logless by design: traffic logs live in memory only and are scrubbed, so we keep no record of where you go.
The free trial
New accounts start with a free trial: use SmokeVPN fully - every server, both proxies, multiple devices - until you reach either the trial's data allowance or its time limit, whichever comes first. After that, subscribe to keep going; your device configs stay exactly the same.
Your remaining allowance shows on your dashboard. For exactly what we do and don't record, see our Privacy page.
Your account number is your only credential
There's no email or password. Your 16-digit account number is your login - anyone who has it can use your account, and it cannot be recovered if you lose it.
Save it somewhere safe (a password manager is ideal) and keep it private.
Default exit
Your default exit is where a device leaves the internet when it's set to Account default. You set one default for the whole account, and every device left on "Account default" follows it. The modes:
- Random - each new connection uses a different server from the pool.
- Timed - rotates to a new random server every so often. Open connections are never dropped; only new ones move.
- Single - always one specific country/server you choose.
- Tor - routes through the Tor network (slower; for maximum anonymity).
- Pool - rotate (Random or Timed) within a custom set of exits you pick.
Any device can override the account default with its own exit from the Devices list.
DNS filtering (ad & tracker blocking)
SmokeVPN runs its own logless DNS resolver - the part that turns website names into addresses. Because it's ours, your lookups aren't handed to a third party, and we can block unwanted domains before they load. Choose what each device blocks from the DNS button in the Devices list - changes apply instantly, no reconnect needed.
- Ads & trackers - advertising and tracking domains. On by default.
- Malware & phishing - known malicious and scam domains. On by default.
- Adult content - pornography domains.
- Gambling - online gambling and betting domains.
- Social media - Facebook, Instagram, X, TikTok and similar.
A blocked site simply won't load ("server not found"); ads inside pages just don't appear. Prefer your
own resolver? Set DNS in your WireGuard config to anything you like - you're never locked to
ours, though our blocking only applies while you use it.
Routing rules (send a destination out a chosen exit)
A routing rule sends traffic for one destination out an exit you choose, while the rest of your traffic keeps using its normal exit. For example: send a streaming service through one country and leave everything else on your default exit.
- Destination - a domain (e.g.
netflix.com), an IP address (e.g.1.2.3.4), or a range in CIDR form (e.g.1.2.3.0/24). A domain rule also covers its subdomains, sonetflix.comincludeswww.netflix.com,api.netflix.com, and so on. - Exit - the specific server that destination should use.
- Applies to - all devices on your account, or a chosen set: pick one or more devices from the list (a "Select all" is there too). Pick every device and it's just "All devices".
When destinations overlap, the most specific rule wins: a single IP beats a range it
sits inside, a deeper subdomain (live.netflix.com) beats its parent
(netflix.com), and a rule for one device beats an all-devices rule. You never have to
order them yourself.
Domain rules need SmokeVPN's DNS. We route a domain by the addresses our resolver
returns, so the device must use our DNS for a domain rule to apply (your config's DNS is set
to ours by default - if you changed it, or your phone uses a "Private DNS", domain rules won't catch).
IP and range rules always work, regardless of DNS.
Rules only affect new connections, so changing them never drops what's already running. If a rule's chosen exit goes offline, that traffic automatically falls back to the device's own normal exit (never an exposed or dead route) - the rule resumes when the exit is back. Add, edit, and remove rules from the Routing rules card on your dashboard.
Exit pools
An exit pool is a set of exit servers you group together and rotate through as a unit. Instead of one specific country or the whole network, your traffic uses only the exits you put in the pool - handy for staying in a region (say a "My EU" pool of a few European countries) while still moving between them.
Each pool has a rotation style, chosen when you create it:
- Random - each new connection uses a different exit from the pool.
- Timed - the exit rotates automatically on a schedule, cycling through the pool. Open connections are never dropped; only new ones move.
Create and manage pools from the Exit pools card on your dashboard: name the pool (up to 20 characters), pick Random or Timed, and choose between 2 and 10 exits. Then point any device, proxy, or your account default at it - open an exit dropdown, choose “Choose a pool…”, and select your pool.
If an exit in a pool goes offline it's simply skipped; if every exit in the pool is down, your traffic falls back to a random working exit (never an exposed or dead route). Editing a pool's exits or deleting it never affects connections already running, and a pool that's in use can't be deleted - reassign whatever is using it first.
Devices
A device is one WireGuard configuration - a config file / QR code you install on a phone, computer or router. Add a device to get its config and QR, import it into the WireGuard app, and you're connected.
Each device can have its own exit, or follow the account default. Your plan includes a set number of devices; remove one to free a slot. Removing a device stops its config from working.
Each device also has its own DNS content filtering - block ads, trackers, malware and more. Set it from the DNS button next to the device, or when you add a new one.
Proxies (SOCKS5 + HTTP)
Besides WireGuard devices, your account has two always-on proxy endpoints - one SOCKS5 and one HTTP - that do not count toward your device limit.
Put the address, port, username and password from your dashboard into any app's proxy settings (a browser, a scraper, etc.) to send just that app through SmokeVPN. Each proxy has its own exit, set independently, and SOCKS5 and HTTP are separate.
Each proxy also has a </> code button that gives you ready-to-use snippets - Python, curl, wget, PHP, Go, Node.js, Ruby and PowerShell - with your address and credentials already filled in. Copy one, paste it, and you're running.
Note: outbound port 25 (SMTP) is blocked on the proxies to protect our shared exit IPs - send email through your provider's submission port (587 or 465). See Limits & acceptable use.
Exit network & latency
The exit network is the list of servers you can route through. Latency (in milliseconds) is the round-trip time to a server: lower is better - a lower-latency server feels faster.
Latency mostly tracks distance. A server geographically closer to you usually has lower latency; one far away has higher latency. "Online" servers are ready to use; "Offline" ones are temporarily unavailable. The list is sorted fastest-first by default.
Plans & payment
Subscriptions are paid in cryptocurrency. Pick a plan - the longer the plan, the cheaper per month. Once your payment confirms, your account activates and your devices and proxies unlock.
All sales are final (no refunds). Contact us with any billing question and we'll help.
Limits & acceptable use
Sending email (SMTP). Outbound port 25 is blocked on the proxies to keep our shared exit IPs off spam blacklists, so a mail app pointed at port 25 through a proxy won't connect. Send mail through your provider's submission port instead - 587 (STARTTLS) or 465 (SSL) - which work normally.
Shared exit IPs. You share each exit's IP with other users - part of what keeps you anonymous in the crowd. Occasionally a site may show a captcha or block a shared IP; switch to another exit or pool if that happens.
You're isolated from other customers. Every account is its own private network: other users can't reach your devices and you can't reach theirs. Your own devices on one account can still talk to each other, like a small private LAN.
Acceptable use. We're logless and don't monitor what you do - but illegal or abusive use is not allowed and puts the whole shared service at risk. No spam, and zero tolerance for child sexual abuse material. The full list is in our Terms; accounts used for prohibited purposes can be suspended or terminated without a refund.