Skip to content

Free residential exit

Many streaming and AI services check who owns an IP: datacenter IPs get blocked, home-broadband IPs get through. PSM can give your nodes a residential (home-broadband) exit for free, and send only the traffic that needs it that way.

Where it comes from

The exit comes from VPNGate, a public VPN relay project run by the University of Tsukuba in Japan, with nodes offered by volunteers around the world, so it costs nothing. From its public list, PSM:

  1. looks up who owns each IP and keeps only genuine home broadband, dropping datacenter IPs and VPNGate's own relays;
  2. connects to one of them with openvpn, as a tunnel used only for routed traffic;
  3. adds it as an exit in Xray, sing-box or mihomo, and routes services such as Netflix and ChatGPT through it by rule.

What you get

  • You pick the country: the list shows only countries that actually have nodes, with how many each has.
  • Automatic failover: with auto-rotate on, a failed node is replaced by another in the same country, so the exit country never drifts.
  • No leaks through the datacenter IP: if the tunnel is down, traffic that matches the rules fails instead of going out through the datacenter IP.
  • The server itself is untouched: the tunnel uses its own routing table, so the server's own traffic, SSH and other nodes are unaffected.
  • Shared by all three cores: Xray, sing-box and mihomo use the same tunnel; switching residential nodes changes nothing in the core configs.

Turning it on

In any core's menu (Xray, sing-box or mihomo) open Routing, then VPNGate residential-IP unlock exit (for sing-box and mihomo: main menu 2 or 3 → 5 → 11):

VPNGate residential exit menu

The first option does it all:

One-click setup (scan -> connect -> outbound -> unlock rules)

PSM scans for usable residential IPs, asks for the country, and once a connection works, writes the exit and adds common unlock rules. The other options:

OptionWhat it does
Scan for usable residential IPsfetch and filter the list again
View the candidate listsee which candidates there are
Connect a specific candidate by numberchoose the node yourself
Switch to another residential nodemove to another node (same country)
Show the real tunnel exit IPconfirm the exit IP in use
Add common unlock routing rulesadd the usual Netflix, ChatGPT and similar rules
Auto-rotate on failure: on / offcheck regularly and switch when a node drops
Export the .ovpn configexport the current node as an OpenVPN config
Disconnect and remove the residential exitclose the tunnel and remove the exit from the core configs

To send more websites through it, route them to this exit under Routing, by domain or by rule set.

Good to know

  • Nodes are run by volunteers, so speed and uptime are not guaranteed: use it for the few services that need it, not for all traffic.
  • Traffic passes through a volunteer's machine: do not route sensitive traffic such as online banking through this exit.
  • The streaming and AI unlock checkers in the System menu show whether it works.

Released under the AGPL-3.0 license · For lawful use only; follow the laws where you live