Nothing comes up at all: not the app you have had for a year, not a new one, not a paid one. The phone says “Connecting…” and then nothing, while Wi-Fi is fine. The usual reaction is to blame the carrier and go change the port on some forum’s advice. We took these cases apart using our own connection log and a test bench in Moscow — and the three most common causes turned out to be nowhere near where people look for them. One of them is barely written about anywhere, and it takes ten seconds to fix.
In short. If no app comes up at all, it is almost always one of three things. Another such app is already running on the phone and holding the single slot the system hands out — ten seconds to fix. The carrier recognises the connection by the shape of its first packet, and moving the port is pointless: we measured that. Or your signal is weak, which looks exactly like interference. Payment affects none of the three. But the first thing to do is not to hunt for the cause — it is simply to try again: in our log for 3–8 September, out of 91 failed attempts 60 succeeded on the very next attempt by the same person, with no setting changed.
We build Mayak. Our own servers in the Netherlands, Poland and Russia, an honest marker on screen showing which path you are on, and measurements we publish as they came out. 7 days free once you confirm your email, no card needed. The trial is free and needs no card; without an email it is 3 days.
🍎 On iPhone Mayak works through the third-party Happ app — with the subscription link from your account. Happ is not in the Russian App Store; there incy (publisher LLC ITDEV) works instead, checked on 22 September 2026.
First tell the three pictures apart
“It does not work” looks like three completely different things on a phone, and they have different causes. Before changing anything, work out which one is yours.
- It never connects. “Connecting…” hangs for a minute and gives up. The connection never gets established — so something interferes at the very start of the conversation.
- It connects and dies two or three seconds later. The “Protected” badge appears and traffic stops. That is a different break: the start was let through and the flow was cut. Full write-up — connected, but no internet.
- It stays up, then drops on its own after minutes or hours. Usually that is the phone, not the network: in 143 of our 158 connectivity checks the phone was keeping the app on a battery leash. Write-up — the VPN disconnects by itself.
The rest of this article is about the first picture: when nothing comes up, one app after another. That is what people describe as “none of them work”.
⚠️ One case looks like the first picture but works differently: on a mobile network in Russia only a list of approved services is left open — the government portal and the bank work, nothing else does. It takes one step to tell apart: on Wi-Fi everything opens. About that mode — Russia’s mobile internet whitelist: what still works.
The cause almost nobody mentions: the slot is taken
Android allows exactly one such connection on a phone. While the slot is held by another app — the one you installed six months ago, tried once and forgot to remove — a new one will never come up. Not “slowly”, not “sometimes”, but never. And the person sees exactly what they see: “Could not connect”.
This is not reasoning. On 2 September someone signed up with us, connected once, and then failed every single time: six attempts in a row, not one of them cleared even the first step. They wrote to support and deleted their account 49 minutes after signing up. Taking the case apart, we saw that at the same time their phone was reaching us from an address that was not ours — meaning a second such app was running on that phone and holding the slot. Forty-nine minutes: a person left without ever seeing the product.
How common is it? Honestly: we only started counting just now. The flag “another app was already running before this attempt” appeared in the log on 2 September, and not every build knows how to report it. Since then, through 5 September, the flag arrived with 49 attempts from 10 people, and on two attempts by one of them the slot really was taken. That sample is tiny and you cannot compute a share from it — but the phenomenon is real, and it cost us a person in 49 minutes.
What to do about it. Open the app list on your phone and check whether a second one of these is installed — often a forgotten free extension or a trial. Disable or remove it and try again. In our app the same thing is reported by the “Check connection” button in settings: it walks every step and names the one that failed.
“Move it to port 443” — we tested that. It does not help
This is the most common advice on the internet: put it on 443, that is where all the web traffic goes, and they will leave you alone. We tested it directly — a measurement where exactly one thing changed. Moscow, Megafon, 4G+, 28 July 2026.
| What changed | Port | Masking | Result |
|---|---|---|---|
| as shipped | 51820 | no | ✗ never connects |
| “move it to 443” | 443 | no | ✗ never connects |
| masking | 443 | yes | ✅ the connection came up |
| masking on an ordinary port | 51822 | yes | ✅ came up, and was faster |
The conclusion was unambiguous: the port number decides nothing. What works is how the contents look — the port is only the writing on the envelope. So if you have spent half a day moving ports with no effect, you did nothing wrong; you were turning the wrong knob. The full breakdown with numbers — what actually decides it on Megafon.
It is the content of the first packet, not its size
The next measurement separated size from content, and it is the most telling one of that day. We sent a packet of exactly the same size as the working variant but without a real signature — 1200 random bytes. It did not pass. Then we sent 20 bytes — sixty times smaller, but carrying the real signature of an ordinary network request. It passed, and then ran at 109 Mbit/s on excellent radio (idle jitter 6 ms — a clean measurement, not a lucky one).
So what is inspected is neither the volume nor the address, but the shape of the first bytes. That is exactly why “none of them work”: if an app always says hello in the same recognisable way, it will trip over the same network as many times as you like — and reinstalling, paying and changing your plan will change nothing.
“But I pay for it”: why a paid VPN does not work either
People ask this one separately and in their own words — “I bought it and it does not work”, “I paid and got nothing”. Behind it is a fair expectation: money changed hands, so somebody should have taken care of this. The answer is short and unpleasant: your payment never reaches the place where your connection trips.
Look at the three causes above. The slot in the system is held by another app — that is a setting on your phone. The shape of the first packet is set by the program — that is its code. The quality of the radio link is set by the cell — that is the tower outside your window. Paying buys none of the three, so looking for the cause in your payment is pointless. The opposite is not true either: it is not “paying is useless” — it is “that is not what you are paying for”.
What the money actually buys. Several routes to the server and an app that moves between them by itself; someone to answer when it breaks; and updates when the network changes its behaviour — in the test above, the difference between “does not connect at all” and “109 Mbit/s” was made by masking the first packet, and only recent builds have it. What money never buys is an exemption from a filter. The filter cannot see your receipt; it sees the shape of the bytes. The full breakdown with numbers is in a separate article, “Paid VPN not working: what money buys and what it does not” — including the case where the money left and the access never arrived, and the order to check things in.
A separate case: “I paid for a data bundle and there is still no internet”. This one may have nothing to do with filtering. Inside a tunnel the operator sees one flow to one address and cannot tell a messenger from a video. So plan perks of the “unlimited for app X” kind do not apply to traffic inside the tunnel: all of it goes into the general counter and runs out faster than you are used to. We have no measurement of our own on billing — this follows from how a tunnel is built, not from our logs, and we say so plainly. The tell is simple: it is the operator itself that writes about the bundle, and without the tunnel the internet behaves the same way. Then it is the plan that needs fixing, not the VPN.
Do not buy blind. Whether such an app works is a property of your network: your SIM, your district, your evening hour. That can only be checked on the spot and in advance. This is why our trial is free and needs no card — so that “it does not come up” happens before you pay, not after.
Three networks behave differently, and one does not interfere at all
On the same July trip we tested three networks in Moscow, and the pictures differed.
- Beeline — the control network: everything passed, including the variant with no masking. So if you are on Beeline and it does not work, the carrier is the wrong place to look — the Beeline write-up.
- Megafon — cuts earlier and harder: no handshake at all, a minute of “Connecting…”. With masking it comes up and works — nine measurements on Megafon.
- MTS — lets the start through and cuts the flow after two or three seconds. Different symptom, similar remedy — the MTS write-up.
And worth knowing: there are four physical mobile networks in Russia — MTS, Megafon, Beeline and Tele2 (also t2, also Rostelecom mobile). Everything else is a virtual operator on someone else’s towers: Yota lives on Megafon’s network, T-Mobile and SberMobile on Tele2’s. So “none of my friends can get it to work” often means “we are all on the same network”. We did not test Tele2 at all — what follows from that has its own write-up: Tele2 and t2.
“It stopped on a particular day”, “only at night”, “but it works in the next town”
A separate scatter of questions is about coincidences. It stopped working on a particular day. It fails at night and works during the day. It has been failing for four days straight. A friend on the same operator is fine and you are not. It works in one town and fails thirty kilometres away. None of that is imagination: the coincidences are real, and they have a simple explanation.
If your question is exactly that — it worked yesterday and stopped today — there is a step-by-step walkthrough of its own: VPN stopped working: what to do. What follows here is about coincidences of place and time: why it works in one town and fails thirty kilometres away.
A mobile network is not one thing. Your traffic goes through the equipment of whichever piece of the network you are attached to right now: a different tower, a different district, a different region means different equipment and possibly different settings on it. So the same operator behaves differently in two places, and one place can change on some given day.
How large that difference gets is visible in our own test: on one day, in one city, on three networks we got three different pictures — one let everything through, one would not even say hello, one accepted the handshake and killed the stream two or three seconds later. If a spread that wide fits into a single city on a single day, “works here, fails there” needs no conspiracy.
What we do not know and will not invent: what the operator changed, and when. We do not see its settings and have nothing to do with them. Anyone who names you an exact date and an exact reason is guessing — and in our experience guessing wrong: twice we explained a failure by filtering and the culprit turned out to be a weak signal (see the section below).
What we do know is how to split the causes in a minute:
- Wi-Fi versus mobile. The same connection comes up on Wi-Fi but not on mobile — it is the cellular network. It comes up nowhere — the cause is in the phone, and it is covered at the start of this article and separately: why a VPN will not connect.
- Another phone on the same network. Your neighbour is fine, you are not, same operator — then the network is not to blame. Usually it is different app versions (only recent builds mask the first packet) or a taken slot.
- Check which SIM carries the data. The phone sends traffic through whichever SIM is selected for mobile data. Swap the SIMs, change that setting, insert a new one — and you are on a different network although nothing changed on the outside. The same explains “it broke after I changed the network type”.
- Look at the idle jitter (how — below). Hundreds of milliseconds mean you are measuring a weak signal, and any conclusion about the day or the city is void.
And about “it has been failing for four days”. In our connection log over 30 days (measured on 5 September 2026) mobile internet succeeds in 88.8 % of attempts and Wi-Fi in 94.8 %. An ordinary failure is one attempt in ten, not four days in a row. When it fails every time and everywhere, the cause is almost never the network — it is stuck on your side: a taken slot, an old build, a setting nobody put back. The numbers are ours, for our people and our app over one month; another month and another city may look different.
A weak signal looks exactly like interference
This is the section about how we got it wrong twice ourselves — and why it is worth checking your link before blaming the carrier.
- We decided the filter was stricter on 4G+, because everything was bad there. We rechecked — it was a back room with a weak signal: idle jitter 1058 ms at a ping of 84. That is a terrible radio link, not suppression. Hypothesis rejected.
- We decided our address specifically was being throttled: speed dropped to 2.6 Mbit/s. We repeated half an hour later on a good link (jitter 29) — 96.9 Mbit/s, the same as on the bench. Hypothesis rejected.
The practical rule is simple: look at the idle jitter first. If it is in the hundreds of milliseconds, any conclusion about the carrier is void — you are measuring a bad cell. Move to a window, wait for a different spot, and repeat.
Your speed meter can be wrong by a factor of fourteen
Another trap for anyone whose connection “got slow”. On 28 July, on the same connection twenty minutes apart, one popular meter showed 2.91 Mbit/s and another 41.98 Mbit/s. It was not the networks that differed but the instruments — by fourteen times. A control run without the tunnel in the same minute gave 139.51 Mbit/s: the cell was fine.
So “it got slow” on its own proves nothing until you have measured twice with different tools. How to measure honestly — why speed tests disagree.
What to do when no VPN works: the one-minute order
- Try connecting again. This comes first, and not out of politeness: for 3–8 September, out of 91 failed attempts 60 succeeded on the next attempt by the same person, and in 45 of those 60 the same direct path worked — there was nothing to fix. The full numbers — VPN stopped working.
- Check whether the slot is taken. A second such app on the phone — remove or disable it. This is the fastest and the most underrated check.
- Update the app. Masking exists only in recent builds; older ones cannot do it at all, and on Megafon and MTS that alone decides everything.
- Look at the idle jitter. Hundreds of milliseconds means you are measuring a weak signal, not interference. Find a decent link first.
- Measure the speed with a second tool. A severalfold difference means the tool is lying, not the channel.
- In our app — “Check connection” in settings. It walks every step in turn and names the one that failed, instead of a blanket “could not connect”.
Here is how we do it. The app tries several paths to the server on its own and verifies each with a real request, and the screen honestly marks which path you are on right now — how that works.
🍎 On iPhone Mayak works through the third-party Happ app — with the subscription link from your account. Happ is not in the Russian App Store; there incy (publisher LLC ITDEV) works instead, checked on 22 September 2026.
What these numbers do not say
So that nobody mistakes our measurements for a verdict on a carrier:
- Every network measurement is Moscow, late July 2026, one phone. In another city and another month the picture may differ.
- We did not test Tele2 at all, and we did not measure Yota separately — we judge it by Megafon’s network, which it runs on.
- The “slot taken by another app” flag was reported by 10 people over four days. That confirms the phenomenon is real; it is not a share and not a statistic.
- Our connection log contains our own devices too — we say so everywhere we quote figures from it.
- Part of the September rise is ours, not the carriers’. One of our lines (the German one) had no backup paths configured until 22 September: whoever failed on the direct path did not connect at all. Without that line the share of failed attempts over 16–22 September is 16.3 % instead of 24.4 %. We found it on 22 September and fixed it the same day; we write it down here because otherwise our own numbers would read as an accusation aimed at someone else.
Short answers
Why will a VPN not connect? If nothing comes up at all, the cause is almost always one of three: a taken slot in Android (see above), a recognisable shape of the first packet (see above) or a weak signal (see above). The port has nothing to do with it: we tested that separately.
What is going on with VPNs today? What the carriers changed, and when, we do not know and will not invent — we only see our own log. In it the share of failed attempts rose from 5.6 % (21 August — 2 September) to 15.7 % (3–8 September), and 61 successful connections out of 580 attempts in those days went through the backup channel instead of the direct one — the full numbers. We came back to the same log on 22 September: it has not recovered. The direct path failed on 26.6 % of attempts over 9–15 September and on 30.9 % over 16–22 September (1,927 attempts, 107 people) — against 11.9 % in late August. So this is not a one-week spike: it has held for three weeks running.
Which VPN works right now? We do not speak for other services and we do not publish rankings: we cannot measure someone else’s app, and repeating someone else’s promises would be dishonest. About our own we speak with a number: for 3–8 September our log holds 489 successful connections out of 580 attempts — every sixth attempt failed. That is our people and our app over six days, not “it works for everyone”.
Why does a paid VPN not work? For the same reasons a free one does not: a taken slot in Android, a recognisable shape of the first packet, a weak signal. Paying buys none of the three — see above. Money buys an uncrowded server, support and updates, not an exemption from a filter.
I paid and it does not work — what should I do? Start with the ten-second check: is there a second app of this kind on the phone? Android allows exactly one, and while the slot is taken a new one will never come up. Then update the app and look at the idle jitter.
“You already have a data bundle, use it up first” — is that about the VPN? Most likely not, it is about your plan. Inside a tunnel the operator sees one flow to one address, so per-app unlimited perks do not apply and the general bundle drains faster. We have no measurement of our own on billing and we say so — more here.
Why did it stop working on a particular day? What the operator changed, and when, we do not know and will not make up. What we do know is the check that halves the problem: the same connection on Wi-Fi. It works — the cellular network; it fails everywhere — the phone.
Why does the VPN fail at night or all day long? The cell is loaded differently at night, and a weak signal looks exactly like interference: in a back room our idle jitter reached 1058 ms and we took it for suppression ourselves. Look at the jitter first.
It works in one town and not in another — why? You are attached to different equipment. In our test a single day and a single city produced three different pictures on three networks — a spread between districts and regions should surprise nobody. How to check it yourself.
It fails for me and works for a friend on the same network. Then the network is not to blame. Compare app versions (only recent builds mask the first packet) and check whether your slot is taken.
I swapped SIMs and the VPN stopped working. The phone carries data over whichever SIM is selected for it. After the swap you are most likely on a different operator — check which SIM is selected for mobile data.
Do your numbers apply everywhere? No. The network tests are Moscow, late July 2026, one phone. The success shares come from our connection log: the 30 days to 5 September, and separately 3–8 September (580 attempts, 27 people), for our people and our app. We did not test Tele2 at all.