© 2022 CoolTechZone - Latest tech news,
product reviews, and analyses.

If you purchase via links on our site, we may receive affiliate commissions.

ASTRILL VPN REVIEW: Good for China but has security issues

6

Astrill VPN makes an impression of a very capable VPN service that can even bypass the Great Firewall of China. It doesn’t just use regular VPN technologies but also implements innovative VPN protocols and allows tuning a safe connection very precisely.

However, the prices of Astrill’s services are really over the top. At first glance, it seems reasonable: a respectable VPN costs a corresponding amount of money. I tried to dig into the tests as deeply as I could to better understand the uniqueness of Astrill and make sure that it is worth $10+ a month.

I could confirm the real efficiency of the service only in terms of some of the expected features. Moreover, I encountered certain difficulties and issues that can pose a serious threat to one’s privacy under some circumstances.

Do you know, for example, that Astrill VPN which sells services aimed at making the Internet anonymous and free, asks for a phone number when you sign up and forbids the citizens of politically sanctioned countries to use its service as well as restricts access to many resources?

And that’s just the tip of the iceberg. There are technical issues, too.

I’ll tell you everything about the confirmed characteristics and the problem I’ve found in this review.

Here are the main characteristics of Astrill:

⭐ Rating:
3.3
🥇 Overall rank:#20 out of #24
📖 No logs policy:Unaudited
💵 Price:From $12.50/month
🖥️ Servers:3000+ servers in 57 countries
🍿 Streaming services:Netflix
🔥 Coupons:-

Astrill VPN pros and cons

Before I objectively rate Astrill, I will provide you with the whole picture of the service, emphasize its peculiarities and interesting features (there are quite a lot of these, actually).

I will tell you about the 7 main peculiarities of Astrill in short. You can find more detailed information about them in the following chapters.

What peculiarities does Astrill VPN have?

1. It uses not one but three ground-breaking VPN protocols along with the standard OpenVPN.

A VPN tunnel is established between the computers and the VPN server to protect data. A certain data transfer protocol – a VPN protocol – is used to do that. The OpenVPN protocol is the most popular one. It complies with the strictest safety requirements but slows the connection down considerably and is detected by tracking devices in China and some other censoring countries as well as many corporate networks.

As of late, alternative independent VPN protocols are on the rise. They don’t have OpenVPN’s flaws. Astrill indicates that it has three new protocols: OpenWeb, StealthVPN, and WireGuard.

2. The most “complete” version of Astrill is the one for Mac.

Unlike most VPNs that have the maximum functionality for Windows, Astrill’s fullest version is for macOS. All 4 protocols supported by the provider are available only on this platform.

3. The highest price among popular VPN services.

Are you willing to pay $10 to $20 per month for the basic feature pack and pay an extra fee of $10 to $100 per month for the VIP pack that allows you to use a chain of VPN servers and the fastest servers?If it doesn’t tell you much, I’ll give you two VPN services as an example:

  • NordVPN, the best VPN of today, doesn’t have any safety issues and costs starting at $3.09 per month. This sum buys you all of its features.
  • Surfshark is a dynamically developed powerful VPN that works in China and also doesn’t have problems with safety. Its prices start at $2.21 per month.

4. Comprehensive functionality.

Settings available in Astrill’s apps (save for mobile devices) are going to surprise even experienced professionals. Jumping ahead, I’ll mention that Astrill has port forwarding, an expanded kill switch, choice of apps and sites that require/don’t require a VPN, and even the ability to share protected Wi-Fi from your desktop (I’ve seen a similar function only on Windscribe).

5. Speed test.

Astrill offers a convenient and effective way to sort VPN locations by speed using the built-in speed test. This isn’t a feature I see a lot. Furthermore, Astrill’s speed test shows real results.

6. Supports Netflix and Hulu.

Streaming is a real strong suit of Astrill. I have tested Netflix and Hulu. If Netflix is supported by at least 10 VPNs, Hulu support is rare. Astrill, though, consistently copes with this task.

7. Port forwarding.

This function is even rarer to come by than Hulu support. It is needed to maximize the torrenting speed.

Nevertheless, I don’t recommend using Astrill for torrenting because of its security problems. Besides, there are reports of the customers who used Astrill for torrenting having issues.

I haven’t enumerated any of the flaws I have found that differentiate it from many other VPNs. We’ll focus on them in the two following chapters.

First steps and first issues of Astrill

The first step you take with Astrill VPN, the signing-up process, is going to bring you the first issues.

After I visited its website and learned about the prices, I chose to pay with a credit card. As usual, I used another VPN to protect my personal data, selected the respective points, and entered my email as most VPNs require. Imagine my shock when after that, Astrill asked me for my phone number!

Astrill VPN requires phone number

This is the first VPN I know of that asks the phone number when signing up. It basically defeats the purpose of using a VPN and destroys the anonymity. But that’s not it. The only phone numbers you can enter are those originating from China, the United Emirates, and the country that my IP address belongs to.

I was hiding my IP with NordVPN and my location was DE. Because of it, I couldn’t enter my phone number. I was only able to register after I turned NordVPN off. Then, the country code that my phone number has appeared on the list.

Immediately, a question popped up in my mind: what if I were abroad and had no access to other VPNs? The answer is self-evident: I wouldn’t be able to sign up for Astrill.I didn’t know the reason for such difficulties at the time but studying their Privacy Policy shed some light on it (more on it later).

Astrill - China

I first learned about Astrill on Reddit where I read comments about how VPNs work in China. There, I found many positive reviews by real users about bypassing the Great Firewall of China.

As I studied the provider’s features and technologies that help to solve this difficult task, I became convinced that Astrill VPN is one of the best VPNs for China.

And here’s why:

  1. Smart Mode is the most efficient and safe solution for China, the UAE, and some other countries;
  2. It has more servers in Asia than most other providers;
  3. 3 (+1 on demand) VPN protocols that are detection-proof.

Let’s discuss all three features in greater detail.

Smart Mode

This mode is only available in China. What it does is connect you not to a foreign but a regional server via the OpenWeb protocol. The regional server then connects to the location the user chooses, providing the IP address change.

This technology fully hides the fact of using a foreign IP address. OpenWeb works in such a way that it bypasses the VPN detection algorithms.

As a result, the user bypasses all the blocks and restrictions with their ISP doesn’t know about it.

Asian market-oriented

Astrill VPN traffic overview

Most of Astrill’s popularity comes from China. In the picture, you can see how traffic is spread by countries according to SimilarWeb. As you see, China accounts for more than 58% of the traffic. The service is also more popular than others in Hong Kong and Taiwan.

Here’s the list of the locations available in Asia:

  • Taiwan (Taipei, Changhua, Nantou, Taichung)
  • Singapore
  • Vietnam
  • Japan (Tokyo, Osaka)
  • Malaysia
  • Hong Kong
  • Thailand

Astrill emphasizes bypassing VPN detection and blocking. It makes 3 efficient protocols available in its basic version:

  1. OpenWeb
  2. StealthVPN
  3. WireGuard

Moreover, the OpenConnect protocol can be added on demand.

All these protocols are some of the most state-of-the-art developments. They are fast and protect the users in China, the UAE, and other countries with censorship.

So, Astrill has everything needed to work under the most pressing political conditions.

Is it one of the best VPNs for China? Undoubtedly, it is.

Research of Astrill: Pros, cons, tests, advice

In this section, I’ll provide you with answers to all the main questions of Astrill VPN’s work. My in-depth analysis has confirmed some of its important advantages but also uncovered several hidden security and privacy-related issues as well as flaws in the app performance and significant differences between functionality on various platforms.

Chapter contents:

Security of Astrill

Security and privacy that a VPN provides are composed of 4 factors:

  1. Hiding the IP address by establishing a virtual tunnel from the client to the VPN server;
  2. Encryption of all the incoming and outgoing information including the addresses of the websites you visit (some VPN apps allow you to set specific programs to be used with a VPN but the default settings always encrypt the entirety of the traffic);
  3. This information is transferred to the virtual tunnel;
  4. Safe DNS is reassigned (thanks to DNS queries, the connection between the visited domain name and its IP address is established).

Astrill VPN has a serious issue with protecting connection safety. I have found three issues with factors #2 and #4. Any connections from the device that go outside of the VPN channel and are not caused by special app settings lead to an IP leak. Besides, unencrypted data can be intercepted at any spot the traffic passes (by bad actors in a public Wi-Fi network, the network administrator, the ISP, or the governmental agencies).

I used Wireshark tuned for traffic interception from the Wi-Fi adapter to analyze Astrill.

First of all, I found a connection outside of the VPN tunnel:

Astrill VPN TCP connection

I found connections to the IP address located in my country (shown inside the red rectangle in the pic above). At the same time, the computer was connected to the US location of the VPN. It means that some part of the traffic is transferred unencrypted.

After I analyzed the traffic transmitted over the course of a longer period, I found 3 IP addresses that my computer had connected to outside of the VPN tunnel:

Astrill VPN tunnel

These IPs are marked red.

I got the same results using all the VPN protocols available in the Windows app: OpenWeb (full protection mode), OpenVPN, and StealthVPN.

Additionally, I found an unencrypted packets leak when using OpenWeb in the full protection mode (outlined in red):

Astrill VPN connection leaks

The address of the VPN server is shown in blue.

As a result, I found two problems at once: a part of data goes outside of the VPN tunnel and at least some of it is unencrypted.

OpenWeb has another issue: not all DNS queries go through the channel (though the settings show the DNS of Astrill). Some of the queries went to my ISP:

Astrill VPN DNS leaks

An unencrypted address of the website I was visiting sent to the DNS server of my ISP is clearly seen inside the red rectangle in the image.

I publish such a detailed report to prevent any possible attempts to protest the test results.

Astrill features tests

In this and the following sections, I will delineate the functions of Astrill that are available with the basic paid plan. To get access to other VPN protocols, you have to contact the support team. Additional features are also present in the VIP packet which I will tell you about in the “Analysis of prices and plans of Astrill VPN” section.

Let’s move on to the tests of features and characteristics of Astrill. In this section, I judge its speed, quality and functionality of the apps for various platforms, test the service’s performance with Netflix, Hulu, and torrents, and analyze its privacy policy which contains shocking facts incompatible with the free Internet.

1. Speed

Speed is Astrill’s strong suit. All the locations tested showed an above-average result:

LocationDownload/upload speed (Mbps)
Los Angeles, US66/47
Netherlands75/53
China27/15
Thailand34/14

It should be noted that Astrill caters to the Oriental market. It has more Asian locations than most of its competitors save for, perhaps, VPN Gate who offers more IPs in the Asian region.

2. Streaming

Another advantage of Astrill that is in especially high demand lately is the unblocking of geo-restricted video content. Streaming services take active countermeasures against VPNs to protect their contracts with rightsholders.

Only a small fraction of VPN services help watch Netflix. Astrill is also capable of consistently bypassing Netflix and Hulu blocks.

For some reason, Astrill removed its webpage on streaming and many other features (you can view its incomplete saved copy) in 2019. Today, there’s no full list of streaming services and TV channels that this provider supports.

I could only find a mention of a few of them:

Streaming services that are suppported by Astrill VPN

3. Torrenting

Torrenting with Astrill is a controversial activity. On one hand, Astrill allows it and has an advanced kill switch and special servers with port forwarding. On the other hand, Astrill leaks data by not packing the entirety of traffic into a VPN tunnel.

I have also found a negative user review speaking about a customer’s issues with their ISP after torrenting with Astrill:

Astrill VPN for torrenting

It’s unknown what settings this user had launched Astrill with but the combination of the technical issues I found during the tests and the case described by the user is a convincing reason to look for another VPN for torrenting.

4. Google search and the use of Gmail

Within 5 days of testing, I didn’t have a single problem with accessing Gmail. Google search also worked without asking for verification that the user is not a robot (which happens with some other VPNs).

5. IP leak test with an unstable connection

It only makes sense to test how reliable the VPN protection is under duress (unstable connection, moving from one access point to another, etc.) when a VPN app has the kill switch function that blocks the traffic if a VPN tunnel fails.

Astrill doesn’t have a kill switch on Android and iOS. In case there is a kill switch despite not being listed in the settings menu (CyberGhost VPN works like that – it doesn’t have a kill switch in its settings but it is integrated into the apps for mobile devices), I checked how Astrill for Android behaves in non-standard conditions:

Astrill VPN Kill swich feature for Android

You can see in the picture how the device’s connection to a network changes.

First, a virtual IP address is determined (the VPN is active). Then, as the Internet connection is lost, the VPN turns off while the device searches for an available network (Reconnect). Then, the smartphone connects to a new network and the real IP address is being leaked for as long as it takes Astrill to restore its connection to a VPN server. The same thing takes place on iOS.

It confirms that the mobile apps don’t have a kill switch and, therefore, do not protect your data and location during a connection loss, switching to another access point, and other cases.

If you need a VPN that protects you reliably under any circumstances, you might want to try NordVPN or some other VPN service out.

6. Other issues with Astrill

In this section, I will enumerate other issues and flaws I’ve encountered more than once during my tests of Astrill.

  1. Frequent DNS issues. During the tests, Astrill couldn’t open websites many times.
Astrill VPN connection issues

It happened both while working and after a long time of being idle during the night.
An inexperienced user may get “trapped” for a long time solving this problem. It can be solved by turning the VPN off and if that doesn’t work (which has also happened), by reconnecting to the Wi-Fi network.

2. Lack of protection with the VPN on. When I was testing the VPN Sharing function, the PC app lost its ability to protect my IP address and traffic. Even after I turned that function off, Astrill didn’t resume working.

3. Weird behavior of the Android app. While the team of Astrill works hard to further develop the service, supports operations in China as well as Netflix and Hulu, offers state-of-the-art protocols, it is also responsible for a weird app for one of the most popular OSs, Android.

4. WireGuard is only available on macOS, Linux, and Android. It is arguably the best protocol supported by Astrill but it’s not present on Windows and iOS.

Astrill for Windows

Most of the cons I have listed concern the Windows app more than others. Astrill doesn’t offer WireGuard and has DNS issues on this platform.

What features of Astrill are available on PC?

  1. Three VPN protocols;
  2. Choosing specific sites or apps to work with the VPN;
  3. Port forwarding;
  4. VPN sharing. It’s an interesting feature that allows using the VPN on the devices connected to the same router as the computer. It requires you to adjust some of the system settings of the devices you connect. Be careful with this function, though. When I was testing it, I discovered an issue with the VPN connection. My computer lost its protection despite the app being shown as active.
  5. Expanded kill switch. It contains two options: App Guard and Kill Switch in the Privacy menu. You can set just certain apps as well as the entire traffic of your computer up.
  6. Speed Test, an effective way of checking the speed of the VPN server you need with high precision.

You can download the Astrill app for Windows from this page of its official website.

Astrill for Mac

As I have mentioned already, the fullest version of Astrill is the Mac one. Only the app for this platform and the Linux one support all 4 protocols including WireGuard. Other than that, this app copies the functionality of the version for Windows.

I encountered the same DNS failures while testing the macOS version as on PC.

I found no unencrypted data leaks or connections to undesirable DNS servers. This, however, is more likely a result of not running as many programs and utilities on Mac as on Windows.

You can download the Astrill app for macOS from this page of its official website.

Astrill for Android

The app for Android is very different from the desktop versions. It doesn’t have the most extra features and settings.

Available features:

    • Three VPN protocols (WireGuard is available while OpenVPN is not);
    • Application filter (sets the VPN up for definite apps)

    I should note that the app doesn’t have a kill switch, which makes it unsafe for torrenting.

    On the opposite side, you can go to the Android safety settings menu right from the app. There, you can remove Astrill from the list of apps that are turned off in sleep mode. Many other VPN services lack such an option, sadly.

    Astrill VPN doesn’t offer an APK installer. You can download Astrill’s Android app only from Google Play Market.

    Astrill for iOS

    The functionality of the version for iPhone and iPad is barebones. Only one protocol is available for iOS (I couldn’t determine whether it is OpenVPN or StealthVPN). At the same time, there are no settings but the choice between TCP and UDP and port selection.

    It’s nothing out of the ordinary, though. iOS apps made by most VPN providers have very few functions (even fewer than Astrill).

    You can install Astrill for iOS from the Apple App Store.

    Astrill warns us:PLEASE BEWARE OF IMPOSTER APPS

    There are multiple fake apps on the App Store - some disguise as Speed Testing apps, some as Astrill Free VPN app, some just use star logo, blue colors and VPN in name. Do not log into these fake apps, as they will steal your login details. Do not pay through these imposter apps, as you will lose your money. Only download Astrill app using official link below. If in doubts, contact our support via Live Chat or e-mail.

    Astrill for Linux

    The Linux version is identical to the one for Mac.

    Astrill’s software for Linux is available as a .DEB file.

    The .deb installer can be downloaded from this page of the official website of Astrill.

    Astrill for other platforms

    Astrill VPN doesn’t offer any extensions for Chrome or other browsers. It also doesn’t have apps for TV platforms as well as Kodi.

    The only software that is available is an OpenVPN applet for Asus Merlin and DD-WRT routers. Astrill also sells routers with preinstalled software. They can be ordered from any country.

    Devices that do not have such software installed can be set up by using multi-purpose OpenVPN settings that are available on the website of Astrill.

    Privacy policy and Terms of service

    In its Privacy policy, Astrill claims that despite storing user activity logs, it deletes all data which can disclose the user’s precise location immediately after they disconnect from the VPN:Our system keeps track of active sessions - connection time, IP address, device type and Astrill VPN application version during the duration of your VPN session. Once you disconnect from VPN this information is removed permanently from our system.

    What does it mean? It means that your IP address is kept while you’re using the VPN.

    Is it bad? Probably not.

    Even had this service not put your IP address down, it would still be quite easy to track active connections without logs.

    Astrill’s Terms of service contain some very important information:

    “You are not allowed to access or use Astrill Services if you are located, incorporated or otherwise established in, or a citizen or resident of:

    • a country or region that is subject to comprehensive U.S. economic sanctions (such as those maintained by the U.S. Treasury Department’s Office of Foreign Assets Control (“OFAC”))
    • a country or region that is subject to comprehensive E.U. economic sanctions
    • Belarus, Burma, Benin, Burkina Faso, Cameroon, Cote D'Ivoire, Cuba, Democratic Republic of Congo, Ghana, Iran, Iraq, Liberia, Niger, Nigeria, North Korea, Senegal, Seychelles, Sudan, Syrian Arab Republic, Togo, United Arab Emirates or Zimbabwe
    • a jurisdiction where it would be illegal according to Applicable Law for you (by reason of your nationality, domicile, citizenship, residence or otherwise) to access or use the Services;
    • where the publication or availability of the Services is prohibited or contrary to local law or regulation, or could subject Astrill to any local registration or licensing requirements”

    So a service intended to help people gain freedom on the Internet and protect themselves actually stands against it.

    At the same time, Astrill’s main market is based on bypassing the Great Firewall of China which is one of the world’s strictest censorships. Then why does it discriminate against other countries so much?

    I checked what happens if you connect to an Astrill server from one of the countries on the list. It turns out, there are no issues.

    It’s impossible to tell if Astrill just tries to secure its noninvolvement in case some trouble happens or actually doesn’t want to help people from the listed countries.

    Analysis of prices and plans of Astrill VPN

    You’d be hard-pressed to find a more expensive VPN than Astrill. And if you take the extra VIP plan into consideration, the price skyrockets.

    Lowest and highest prices of Astrill:

    Lowest price per month$10
    Highest price per month$110 and more

    Such a huge difference between prices comes from the extra features that Astrill provides for a surcharge:

    • Dedicated IPs. $5 for every IP address;
    • VIP add-on. It is aimed at customers from Asia and gamers. It allows using Multi-hop VPN (chaining up to 3 servers), optimizes speeds and decreases latency. This add-on costs $10 to $100 depending on how much traffic is included.

    Prices of the major plans:

    • $20 per month on a 1-month subscription
    • $15 per month on a 6-month subscription
    • $10 per month on a 1-year subscription (+ 3 months for free)

    Astrill can be used free of charge for 7 days. The free trial is available for all countries but China as well as for all platforms and doesn’t require a credit card.

    Astrill doesn’t issue refunds when you cancel your subscription. The reasons it gives are that customers are going to like the quality of services and that they can test how the service work with the free trial.

    Though Astrill doesn’t sell coupons, there is sometimes a time-limited possibility to win one, for example, by playing a simple game on a certain page of the Astrill website. However, this isn’t a reliable method because it involves a lot of randomness: your discount can be anything from 5% to 50% while your chance of getting it is 75%.

    I did not test the features of the trial version because its short duration isn’t attractive for free use.

    History of Astrill and information about the owner

    Astrill VPN location
    Image taken from Google Maps

    Astrill was founded in 2009. Astrill Systems Corp is registered offshore in Seychelles. It is a good jurisdiction that allows the provider to avoid political and economic pressure. Besides, Astrill is located far from 5, 9, and 14 Eyes intelligence alliances.

    The company and its services have never been involved in any scandals or investigations.

    Astrill Systems Corp address:Oliaji Trade Centre, 1st floor,Victoria, Mahe, Seychelles

    Website: astrill.com

    My conclusion

    Quite a sizeable review, isn’t it? During my tests, I have discovered and verified some significant advantages but also serious drawbacks:

    Do I recommend Astrill?

    If you live or travel to China, the UAE, or other countries that restrict the use of VPNs, then my answer is 100% yes!

    It is also a good service for streaming.

    Otherwise, a lot depends on how much you value your privacy because Astrill can leak certain data. If your tasks are sensitive, my advice to you is to find a more secure VPN.

    Don’t hesitate to leave a comment or ask us a question. We’ll be right happy to answer them!


    Comments

    Simp
    Simp
    prefix 6 months ago
    Thanks for the review! I'm using Astrill in China and it seems like my IP is being leaked and I can't find people on LinkedIn. Curious if you've found a solution?
    Anonymous
    Anonymous
    prefix 1 year ago
    there is faked advertisement in Astrill's china server.

    when you try to use china in openweb (that is the only mode available for china), your ip address actually is a singapore ip address.

    Astrill does not have a real China server located inside China.

    You can confirm tbe above by using own https://www.astrill.com/what-is-my-ip
    Tomas
    Tomas
    prefix 1 year ago
    Hello and thank you for the thorough review that actually aims to verify VPN security and does not only decide what VPN is the best based on the largest affiliate commission (as became habit of most VPN review sites).

    I would like to point out, that from your security review, it seems pretty obvious you are using Smart Mode or "Tunnel only International sites" filter. In either cases, local traffic, as well as local DNS traffic, is tunneled over your local ISP connection. This is not a bug, but a feature that allows users who only want to use VPN for the "outside world", but are happy to browse local internet with their home IP. This is useful in multiple cases, some of which include domestic sites blocking foreign IPs with firewall, fast local video streaming which would otherwise be geo-restricted under US IPs and many more.

    I would like you to make sure that neither any Site filter, nor Smart mode is enabled, and retest. You will find that not only does Astrill tunnel and encrypt all your traffic, it also actively prevents DNS, IPv6 and WebRTC leaks. Thanks and looking forward to the update!
    Firegate
    Firegate
    prefix 2 years ago
    Unfortunately didn’t work for me on Linux… failed to connect to the server no matter what.
    fasthegurries
    fasthegurries
    prefix 2 years ago
    Look, I’m not here to badmouth Astrill. It’s like almost the only VPN that actually works in China in my experience, and trust me, I’ve tried a few. However. I think its success got to the executives’ heads a little bit. That’s probably the reason they charge so much for it. It’s really not very funny if you think about it when you have to pay more than a hundred quid a month and the speed you get is what Astrill gives you right now. I really hope the speed gets better soon because as I said it’s a good service to use in China.
    spoonyslostintegrity
    spoonyslostintegrity
    prefix 2 years ago
    Hello! I want to share my experience using Astrill in China. I travelled there for work last month and before I went, I installed Astrill based on the advice from this review and several others. Long story short, I was quite disappointed by its stability. My connection failed all the time and often it was not even able to connect at all! Any idea what it could be???
    Leave a Reply

    Your email address will not be published. Required fields are marked

    Cool Tech ZoneCyber Security Labs & News