Changelog

Every release of BlankTrail Proxy, newest first.

  1. 1.3.11Browser-grade HTTP/3, DNS over HTTPS on the port and a browser TLS handshake

    • HTTP/3 is enabled the way a browser does it: from the HTTPS record on the very first request, and from the Alt-Svc header even for a connection that is already open; on exits without UDP the wait for the record is skipped.
    • DNS over HTTPS right on the port: the DoH address is copied from the dashboard and the query count is shown on the port card; off by default.
    • The Browser preset turns on HTTP/3 and DNS over HTTPS, the HTTP preset turns them off; a preset can also be chosen through the API when a port is opened.
    • The TLS handshake follows Chrome and Firefox more closely: session resumption after the server asks for a new hello, browser-accurate ticket age and message padding, and a fallback to 1-RTT when 0-RTT is refused.
    • Firefox profiles are no longer refused by servers that pick the P-256 group.
    • When the exit is alive but a TLS connection to the site cannot be established, the client receives a 525 status instead of a dropped connection.
    • With an explicitly chosen resolution strategy, a slow provider resolver is given up to 10 seconds, and a port using the provider strategy does not hand names to the exit until the provider is identified.
    • The exit provider is identified even on gateways that spread one session across several nodes, and is checked again after a port has been idle.
    • Queries to DNS servers over TCP and TLS stay within server limits, so answers are no longer lost during bursts of names.
    • DNS answers with forged signatures are rejected in every mode, and answers from an interceptor never reach the port.
    • A TUN port no longer limits the number of connections, since it carries traffic from the whole system; the result of opening MTProto and TUN ports is shown immediately.
    • The xray and OpenVPN gateways work under system-wide capture, and an OpenVPN server can be given by domain name.
    • Chrome and Edge 154 and Firefox 156 profiles.
    • Self-update names the reason for a failure, leaves no stray files in the program folder, and rollback on Windows works.
    • Re-binding a licence to a device is committed reliably, and a damaged device name is not silently replaced.
    • The capture service is installed only from a protected program folder, and its data is accessible only to the system and administrators.
  2. 1.3.10Resilient DNS on unreliable exits, a licence-bound resolver database and gateways in the container image

    • Name resolution copes with exits that stay silent or cut answers short: a resolver that does not answer through a particular exit is set aside for that exit only.
    • Queries to the same DNS server share one connection instead of opening a new connection for every question.
    • Provider resolvers are checked once, not again on every exit change.
    • The provider resolver database is delivered from our server under the licence key; until it arrives, the client retries with a growing pause.
    • If the Google captcha script fails to load through the exit, the check page is reloaded instead of waiting in vain.
    • A failed solve during an exit change is also reported in the X-BlankTrail-Error header.
    • The exit check reports when an exit substitutes TLS certificates.
    • The container image includes the xray and OpenVPN gateways, so tunnels work without extra installation.
    • Older OpenVPN configurations also connect to OpenVPN 2.6 servers.
    • Ports saved by the user are no longer overridden by start-up ports from the configuration.
    • Changing the profile in fixed-profile mode applies the selected profile straight away.
    • An outdated client is told to update — in advance in the licence card, and when the server refuses it.
    • The port card offers ready connection examples for curl, Python and Node, with the login when authentication is on and with DNS resolved through the port.
    • Selecting text past the edge of a modal window no longer closes the window.
  3. 1.3.9Failure codes for clients and ports that survive a restart

    • When an exit is unreachable, the client receives a 523 status instead of a dropped connection.
    • The reason a check could not be solved is reported in an X-BlankTrail-Error header that is easy to parse programmatically.
    • Refusal reasons, a port's exit address and its proxy chain are visible through the API.
    • Ports opened through the API or the dashboard are kept after the client restarts.
    • A port opened from the dashboard no longer closes on idle by default.
  4. 1.3.8Port browser mode, session transfer and a solver fingerprint that follows the profile's OS

    • Port browser mode: requests run inside a solver window exactly as a real visitor would make them, and site checks are cleared in that same window.
    • Browser mode has its own switch in the dashboard, and Challenge Breaker is set with a single choice: off, automatic or forced.
    • A port's session can be exported and imported through the API without reopening the port: TLS tickets, solved checks and cookies travel together.
    • A port's current exit address is available through the API at any moment.
    • On Windows and Linux the solver presents the characteristics of the profile's operating system, macOS included: fonts, audio, screen and colour, WebGPU and shaders match the declared system.
    • WebRTC works only through the port: the STUN address is obtained through the exit and ICE server names are resolved at the exit, so the machine's real address is never exposed.
    • A solved check stays valid for up to an hour.
    • A Google captcha on an interstitial page is solved rather than treated as already passed.
    • For DataDome checks, macOS profiles present the characteristics of a real Mac and a current system version.
    • The client tells a static exit from a rotating gateway on its own.
    • Password fields in the dashboard and the activation wizard can be revealed to check what was typed.
    • Installation on macOS no longer fails silently.
  5. 1.3.6Native ISP DNS, chained SOCKS5 upstreams and a consistent fingerprint across hosts

    • DNS is resolved through the exit provider's own resolvers, so the resolution path matches a real subscriber of that network rather than a public DNS service.
    • The resolver nearest to the exit node is selected automatically, from an updated provider resolver database.
    • DNSSEC signatures are validated: forged answers are rejected, and the authenticated flag is set only for verified responses.
    • An upstream proxy can be given by domain name: the address is resolved independently, without routing the lookup back through the port.
    • SOCKS5 upstreams with username and password are supported on ports.
    • Chained SOCKS5 over SOCKS5, including UDP, so a SOCKS5 proxy can run inside a VPN tunnel.
    • HTTP/3 traffic passes through a port's SOCKS5 upstream.
    • DNS over TCP works on every port entrance, and networks that intercept DNS no longer slow down resolution or port activation — a port through an exit without IPv6 opens in about four seconds instead of ten.
    • Chrome and Edge 153 profiles, plus a reference database covering every stable Chrome, Edge and Firefox version: headers, TLS session resumption and ECH behaviour now follow the specific browser version a profile declares.
    • A browser profile presents the same media, audio and device characteristics whether the client runs on Windows or Linux.
    • Firefox profiles on Android report an Android browser string in automatic mode.
    • Browser extension 1.1.13: cached state, profile editing, port import from the client and gateway latency checks.
    • Tunnels are released cleanly on exit changes, and orphaned tunnels from an earlier run are cleared at start-up.
    • The container image runs under an init process, so browser helper processes no longer accumulate.
    • Port settings transfer without loss when a port is reopened; any field that cannot be applied is named explicitly.
  6. 1.3.5Stable gateways and tunnels, DNS under capture, TLS session resumption

    • Gateways no longer drop requests intermittently, and the client reports its own state instead of staying silent.
    • Ports are never handed a tunnel that has already died.
    • Tunnels no longer lose TCP connections because of an overstated MTU.
    • An OpenVPN gateway keeps working under system-wide capture, and comes up on port numbers Windows reserves for UDP.
    • DNS keeps working on networks that intercept TCP port 53, and under system-wide capture; resolver connections are reused within a limit.
    • TLS session resumption is reproduced per browser version across all transport lanes, and appears in the report.
    • QUIC capture is stable under load.
    • A per-port counter of useful work: requests served between challenges.
    • Solver asset cache with a 5 GB limit, so repeated work does not download again what it already has.
    • The client installs through Homebrew on macOS.
  7. 1.3.3macOS support, captcha API, browser extension, DNS leak detection and resolver control

    • Full macOS support: certificate authority trust, system-wide capture, installer and browser fingerprints.
    • An anti-captcha.com-compatible API: existing integrations work without code changes, RecaptchaV2Task is solved by site key, and the listener is switched on from the dashboard without a restart.
    • The captcha API clears stuck tasks in the background and names the reason when a client proxy is refused.
    • Chrome extension for BlankTrail: port control from the browser, capture mode, resolver hygiene and a theme that follows the browser.
    • DNS leak detection: queries leaving past the tunnel are found and reported, with the resolution path shown.
    • WebRTC leak detection: disclosure of the real address past the proxy is caught and named.
    • Resolver hygiene is enabled by default: the system resolver is replaced rather than merely cleared, and the original setting is restored on rollback.
    • DNS interception works regardless of route, covering port 53 to any address.
    • DNS resolution at the exit node, so queries leave from the same address as the traffic.
    • Exit country is reported consistently and derived from where the address actually operates, not from where it was allocated.
    • Browser fingerprint surface no longer depends on the host: WebGL, shader precision, WebGPU limits and certificate authority visibility follow the profile.
    • Speech synthesis voices and reported device memory follow the profile and stay consistent with one another.
    • Firefox profiles updated to version 155, with HTTP/3 enabled.
    • Substantially higher reCAPTCHA throughput, with per-solve reporting in the dashboard.
    • Queue-it handling no longer triggers on the destination of a redirect.
    • A guided introduction on first launch, with contextual hints and a help panel available on request.
    • Subscription expiry stops the client predictably, and the port limit is reported honestly.
    • A second copy of the client no longer starts silently: it points to the running instance. The tray menu follows the system language.
    • The Linux installer no longer installs an X virtual framebuffer: the solver runs headless by default.
    • Licence revocation lowers privileges immediately, and revoked keys do not survive a restart.
    • SOCKS5 diagnostics name the refusal, and the dashboard copies port addresses in the form clients expect.
    • When a solver process ends unexpectedly, the reason reaches the log and the dashboard.
  8. 1.3.2Leak audit mode, QUIC fingerprint capture and Chrome/Edge 152

    • Leak audit mode with its own report, API and dashboard card: an application's DNS, WebRTC, QUIC and UDP traffic becomes visible in one place.
    • DNS leaks are named rather than numbered, including queries made through the Windows system resolver.
    • When DNS is blocked, the client answers with an explicit refusal rather than silence.
    • Short-lived helper processes are listed in the audit, so traffic cannot hide behind them.
    • The audit log is not inherited between sessions, and switching logs no longer hides findings.
    • Fingerprint capture over QUIC, and a capture mode in which a debug port takes an application's traffic.
    • Chrome and Edge 152 profiles: TCP and QUIC forms captured from live browsers, with matching trust anchors.
    • Light theme is now the default across the dashboard, sign-in and activation screens.
    • Heartbeat interval is set by the server rather than fixed in the client.
  9. 1.3.1Licence diagnostics, device binding and container delivery

    • The client states plainly why a licence was refused and keeps a log of its checks.
    • Licence binding diagnostics are presented in readable form instead of ending in a dead end.
    • Device binding to the licence key with signed heartbeats and orderly replacement when a device is retired.
    • Container image published for deployment alongside orchestrated services.
    • Bundle installation no longer fails on systems that do not create symbolic links.
  10. 1.3.0System-wide traffic capture, macOS support, Docker delivery and Akamai handling

    • System-wide traffic capture: any application is routed through a chosen browser profile without configuring the application itself.
    • Kill-switch for captured traffic, and an explicit direct route that bypasses the tunnel where required.
    • Captured UDP, including QUIC, leaves through the exit of the port that owns the process.
    • macOS builds for Intel and Apple Silicon; the solver bundle is selected by operating system and architecture.
    • Official Docker image with container bootstrap: configuration through the environment, licence activation on first start and initial ports.
    • Akamai Bot Manager behavioural challenges are recognised and handled.
    • A legitimate Akamai response is no longer mistaken for a challenge, so it no longer consumes a solve.
    • A site refusal page carrying an "I am not a Robot" button is no longer treated as a captcha.
  11. 1.2.13DataDome slider captcha support

    • DataDome slider captchas are recognised and solved automatically.
    • Solving works on both the fast lane and the browser lane.
  12. 1.2.12Frame rate control per browser profile

    • Two independent frame rates per profile: the refresh rate a site observes, and the rate actually rendered.
    • Lowering the rendered rate reduces CPU load without changing what the page observes.
  13. 1.2.11Safer handling of intercepting upstreams

    • An upstream proxy that intercepts TLS is refused by default; the client receives a clear 526 response.
    • The behaviour can be allowed explicitly with the allow_mitm_upstream option.
  14. 1.2.10Lower CPU usage and headless operation by default

    • Proxy CPU usage reduced roughly threefold on the same workload.
    • The captcha solver runs headless by default.
    • Pool rotation on errors, and clearer timeout hints in the dashboard.
  15. 1.2.9Faster failure detection on dead upstreams

    • A dead upstream proxy is detected in about a second instead of ninety.
    • Separate connect timeout and request budget for every port.
    • HTTP/2 negotiation failures are logged with their reason.
    • Concurrent solver contexts raised from 10 to 25 on suitable hardware.
  16. 1.2.8Captcha limits and licence recovery

    • reCAPTCHA time limits raised and made configurable.
    • Profile pack is downloaded automatically once the licence server is reachable again.
    • Solver queue is collapsed by default to keep the dashboard readable.
  17. 1.2.7Gateway diagnostics and solver limits

    • OpenVPN connection problems are reported with an accurate reason instead of a generic failure.
    • TLS transport flag for gateway tunnels.
    • Captcha solving time limits raised to 120 seconds.
  18. 1.2.6Gateway subscriptions and solver queue

    • VPN gateway subscriptions with an automatically refreshed gateway list.
    • Five additional gateway protocols, with subscription names and response times shown in the dashboard.
    • Clash YAML subscriptions are supported.
    • Captcha solver queue is visible in the dashboard.
    • Upstream proxy certificate is verified, and the trust setting is available per port and per pool.
  19. 1.2.0Major update: challenge handling and profile isolation

    • Much higher pass rate on Cloudflare challenges.
    • Protection challenges on AWS-hosted sites are now handled.
    • Added support for Google text captchas, in addition to reCAPTCHA supported earlier. Works out of the box, no configuration needed.
    • Ports no longer share language and header settings: each profile stays isolated.
    • Requests are no longer lost when the network connection changes mid-session.
    • The dashboard now shows whether each component is ready, and states plainly why something is unavailable instead of failing silently.
    • The VLESS gateway helper now ships for every platform and matches the machine's architecture, including Windows on ARM.
    • Please update: older versions will gradually stop being supported.
  20. 1.1.47Dashboard polish + log rotation

    • Idle-timer bars now fill correctly again.
    • The upstream column shows the proxy with its protocol, and proxy chains as "first-hop › upstream".
    • proxy.log is now capped by size (rotates to proxy.log.1) so it can no longer fill the disk on long runs.
  21. 1.1.46Config test: TLS passthrough

    • Config test now marks the fingerprint check as N/A when TLS passthrough is on, instead of a misleading certificate error — in that mode the proxy isn't substituting a fingerprint.
  22. 1.1.45Dashboard fixes

    • Config test no longer reports a port that has an upstream proxy as a direct connection.
    • Debug ports can now be closed straight from the fingerprint-capture window.
    • The copy-proxy button now works on plain-HTTP LAN dashboards reached from another machine.
  23. 1.1.44Refreshed dashboard interface

    • Redesigned dashboard with a refined neon interface and clearer status cards.
    • New light theme — switch anytime from the header; your choice is remembered.
    • Polished port table, protocol badges and license banner.
  24. 1.1.42Native DNS (VDNS): geo-consistent resolving & bypass provider DNS filters

    • Each proxy port can now resolve target domains itself, through the tunnel, using DNS servers consistent with the exit IP's location (via EDNS Client Subnet). This keeps your DNS geography aligned with your proxy — a common anti-fraud trust-score factor — and lets you open "sensitive" domains that some proxy providers block at the DNS level. Enable it per port: "On DNS leak" turns it on automatically only when a leak is detected, or "Forced" keeps it always on (for example, to bypass a provider's domain filter). Off by default; pick the automatic curated resolvers or supply your own.
  25. 1.1.41Closer fingerprint match in profile-pool mode

    • In database (profile-pool) mode, choosing a browser version that isn't in the built-in profile set now generates a realistic fingerprint for that exact version — matching the version you configured, or the one in the request's User-Agent — instead of falling back to an unrelated profile. When a generated fingerprint can't be produced, the closest real profile of the same browser is used, never a different browser.
  26. 1.1.40Easier API key & one-click OpenVPN

    • Your API key is now always visible in Settings, with a copy button — no more one-time-only display. You can also set your own custom key instead of only generating a random one, which makes it easier to reuse an existing key across your scripts and integrations.
    • On Windows, when OpenVPN isn't installed the setup wizard now offers to download it from the official site and install it for you — instead of just pointing you to a link. It stays optional and is only needed for the OpenVPN gateway.
  27. 1.1.39Manage from another device

    • The optional "Allow LAN" setting now also exposes the dashboard and control API to your local network, not just the proxy ports — so you can open and manage the app from another device. Access stays behind your dashboard password and API key, and password recovery remains available only from this computer. Enable it in Settings and restart the app for the dashboard to become reachable on the LAN.
  28. 1.1.38Reliable startup after update

    • Fixed a failure where the app could not start after an update on Windows because it lost access to its own data folder (you would see an "Access is denied" error while creating the certificate file). Startup and automatic updates are now reliable, and an install already affected by this is repaired automatically on the next start.
  29. 1.1.37Clearer proxy tests & Windows polish

    • The upstream connection test now reports the real exit IP that sites will see and shows the full chain path. When you route through a proxy chain (a proxy inside another proxy), the result clearly shows both hops and the final exit address, instead of naming only the first hop and looking like the second one was ignored.
    • When you open a port for editing, the upstream and first-hop proxy fields now keep the scheme you typed (such as socks5://) instead of showing only the address.
    • On Windows, starting a VLESS/Reality gateway no longer opens a stray command-line window.
  30. 1.1.36Security & privacy hardening

    • Proxy ports and the dashboard now listen on this computer only (127.0.0.1) by default. Making them reachable from your local network is an explicit opt-in in Settings, so a fresh install is never unexpectedly exposed to other devices.
    • Added optional password protection for your proxy ports: you can require a username and password (SOCKS5 or HTTP) before a port accepts connections. It is off by default and enabled in Settings.
    • Sensitive local files — including the license and the dashboard session key — are now encrypted at rest on Windows and readable only by your account, so other users on the same machine cannot access them.
  31. 1.1.35Reliable automatic updates

    • Fixed automatic in-app updates so new versions download and install correctly. From this version onward installations update on their own; if you are on an older version, install this update once manually and automatic updates will work from then on.
    • Added a safety check that refuses to apply an update file that isn't a valid program, so a failed update can never leave the app unable to start.
  32. 1.1.34Cache privacy

    • BlankTrail still shares one fast response cache across all your ports, but activity on one port can no longer be correlated to another through it: a cached page can't be revalidated in a way that carries a tracking cookie or stored identifier over to a different port (even when your outbound IP changes), and personalized responses that vary by cookie or by who is logged in are never served to a different port. Rotating a port's identity now also clears that port's saved TLS session state, so a fresh identity never resumes an old connection.
    • The Microsoft Edge profile is updated to Edge 150, the current Edge release. Ports emulating Edge now match the latest real Edge across TLS, HTTP/2 and headers.
    • Fixed a rare Windows startup failure where the tray app could refuse to launch when it couldn't create its data folder or open its log file, sometimes requiring a full reboot to recover. It now locates its data reliably alongside the application (with a fallback) and starts even if the log file can't be opened.
  33. 1.1.33Stability fixes

    • Multiple OpenVPN gateways can now be used at the same time — different ports can route through different OpenVPN configurations concurrently.
    • The Microsoft Edge profile now presents a genuine Edge identity (User-Agent and client hints) instead of appearing as Chrome.
    • Ports set to spoof the User-Agent and headers now always apply the chosen browser identity, even without full HTTP/2 spoofing.
  34. 1.1.32Fingerprint fidelity

    • Non-browser clients on HTTP/2-spoofing ports now present a byte-exact browser fingerprint across TLS, HTTP/2 and headers, passing stricter fingerprinting checks.
    • Added a byte-exact Firefox 152 profile.
    • HTTP/3 (QUIC) requests now carry the browser's connection settings, and TLS session resumption is supported — closer to real browser behavior.
    • Response caching now works together with HTTP/2 fingerprint spoofing.
  35. 1.1.31Fingerprint refinements

    • You can now open Android device profiles from the dashboard (previously only Windows/macOS/Linux/iOS were selectable, even though Android profiles ship in the database).
    • HTTP/2 header order is now spoofed to match the selected browser by default, so a port's HTTP/2 request looks like the real browser without any extra toggle.
    • Editing a port's browser/OS now shows the resulting profile immediately in the details panel instead of appearing blank until the first request.
  36. 1.1.30Port pool reliability

    • Upstream-proxy checks and traffic no longer fail on proxies that self-sign or intercept TLS — many residential/mobile proxies do this, and they now pass the reachability, leak and config checks.
    • When an upstream proxy fails, the pool now switches to a different proxy on retry (fast failover) instead of repeatedly dialing the dead one, matching the default rotate-on-error policy.
    • The pool's config test now checks a random live port instead of always the first one, so it reflects the pool as a whole.
  37. 1.1.29Port Pool fixes

    • Pool ports now open as SOCKS5 by default (you can pick SOCKS5 or HTTP in the Port Pool dialog) so UDP and spoofed HTTP/3 work through the pool. Existing pools keep their original protocol.
    • Editing a running pool now correctly restores its proxy-source address and its rotation settings instead of coming back blank.
    • A proxy-list URL pasted into the file/server-path field now downloads correctly instead of failing, and the Advanced settings panel renders properly.
  38. 1.1.28Crash-report banner fix

    • The "previous run exited uncleanly" bug-report banner now stays dismissed. Closing it — or sending a report — no longer brings it back after you refresh the dashboard; it only reappears if the app actually crashes again.
  39. 1.1.27Port Pool & profile view

    • The Port Pool dialog now closes on launch, and each running pool's controls (edit, config test, view profile, stop, export link) live on its row in the Active Ports table. The exported proxy list now carries the scheme (socks5://host:port). You can also download-and-count a proxy source and test a random proxy for reachability, DNS/IPv6 leaks and UDP before launching.
    • The browser-versions panel is now a clean, collapsible list grouped by operating system and browser, and the stat shows how many browser versions the database holds.
  40. 1.1.26Update reliability

    • Automatic updates now retry when a download is interrupted on a slow or unstable connection, and detect an incomplete transfer directly, instead of failing on the first attempt.
  41. 1.1.25Auto-profile display

    • For ports using auto-profile from User-Agent, the dashboard now shows the identity actually served for the last request (for example Chrome after a Chrome request), instead of the initial seed profile.
  42. 1.1.24Port view & config-test fixes

    • Fixes text being clipped at the right edge of the port details and the Profile view (long fingerprint values now wrap), the copy button overlapping the neighbouring field, and the configuration test: it no longer reports a false fingerprint mismatch on Browser/auto ports and its result stays on screen.
  43. 1.1.23Windows update fix

    • Resolves a Windows self-update failure ("Access is denied") where the running application could not be replaced in place; updates now install reliably. Minor Profile-view layout refinement so long cipher and extension lists wrap cleanly.
  44. 1.1.22Port editing & config-test fix

    • Open ports can now be reconfigured in place through a full Edit dialog, matching the Open Port dialog. The configuration test no longer reports a false fingerprint mismatch on SOCKS5 ports, and its result stays visible instead of clearing. Port details are shown in a cleaner read-only layout.
  45. 1.1.21Open Port dialog refinements

    • Quick-start captions above the Browser and HTTP-client presets, consistent option naming in the mode dialog, a steadier pre-flight test layout, stricter upstream validation, and a selectable proxy-string field in the port details.
  46. 1.1.20Interface fixes

    • Dashboard interface corrections: tab layout for longer labels, Open Port dialog sizing, tooltip positioning, and consistent language switching across all elements.
  47. 1.1.19Dashboard in Russian & Chinese

    • The in-app dashboard is now fully localized — switch between English, Russian, and Chinese from the header. Every screen, dialog, tooltip, and message is translated.
  48. 1.1.18Rebranded to BlankTrail Proxy

    • SpoofForge is now BlankTrail Proxy, served at blanktrail.com. Existing installs keep working and update seamlessly — no action needed.
  49. 1.1.17Smarter Open Port presets

    • The Open Port quick-start presets now set a fully coherent identity: the HTTP-client preset assigns and spoofs a complete browser identity, and the Browser preset matches and normalizes the real browser's fingerprint — each with a clear Identity / Uniqueness choice.
  50. 1.1.16Refreshed logo

    • A single BlankTrail Proxy shield logo now appears consistently across the app, the tray and installer icons, and the website.
  51. 1.1.15Scraper task improvements

    • The Scraper Tasks dialog is clearer: upload a proxy list directly or point to a URL, pick any browser or a random mix (and a random OS), with sensible defaults and an Advanced section for finer pool control.
  52. 1.1.14Dashboard overview improvements

    • The main dashboard is cleaner and faster to work with: an adjustable page size for large port lists, one-click copy of a port's proxy address, and a clearer browser-types summary.
  53. 1.1.13Domain routing improvements

    • Domain routing rules now save automatically on every change, with a cleaner editor: guided upstream/gateway selectors and per-field help.
  54. 1.1.12Presets management

    • Redesigned the Presets tab: organize saved port sets in folders with drag-and-drop, save all or selected ports, and apply with overwrite or merge.
  55. 1.1.11VPN gateways management

    • Redesigned the VPN gateways tab: a clear table with inline edit and delete, and a guided add dialog for VLESS and OpenVPN.
    • Gateway chaining (route one gateway through another) now works, with loop protection.
  56. 1.1.10Interface improvements

    • Redesigned the port-opening dialog: one-click browser / HTTP-client presets and a cleaner, guided layout.
    • Test an upstream proxy or gateway (connectivity, UDP, and leak checks) right before opening a port.
  57. 1.1.9Reliability & dashboard refresh

    • Improved reliability of profile and generator delivery.
    • Redesigned dashboard: feature tabs, a settings menu, and a language selector.
    • Clearer connection-status messages.
  58. 1.1.8Gateways out of the box

    • VLESS+Reality gateways now work out of the box — nothing extra to download.
    • If OpenVPN isn't installed, the dashboard now shows how to install it for your operating system.
  59. 1.1.7Password recovery & installer options

    • Forgot your dashboard password? You can now reset it by re-activating your license.
    • On Windows, when an existing installation is detected, the installer lets you choose to update, reinstall from scratch, or remove — and a clean reinstall can keep your license and certificate.
  60. 1.1.6In-app updates

    • Update BlankTrail Proxy to a new version right from the dashboard — one click, with a manual download fallback if an automatic update isn't possible.
    • Further HTTP/3 (QUIC) fingerprint accuracy refinements to match current Chrome even more closely.
  61. 1.1.5Sharper HTTP/2 fingerprinting

    • When the app picks a browser profile from the requested User-Agent, the HTTP/2 layer of the fingerprint now matches that real browser even more closely.
  62. 1.1.4Latest browser fingerprints

    • Updated to Chrome 150, along with the current Firefox, Safari, and Edge.
    • Profiles are more diverse and realistic, so each connection looks like a distinct real machine rather than a copy of the same one.
    • HTTP/3 (QUIC) fingerprinting is fully up to date.
  63. 1.1.3License upgrades & money-back

    • Upgrade your license to a higher plan in place, paying only the price difference.
    • A 48-hour money-back guarantee is now available.
  64. 1.1.0Stronger licensing & integrity

    • Hardened license protection: the fingerprint engine is now delivered securely to your licensed device at startup instead of shipping inside the app.
    • The app connects to your account once at launch to load its profiles; a brief internet connection is required when it starts.
    • No change to how you open ports or use profiles — everything works the same once running.
  65. 1.0.5Fingerprint tools

    • Config test: one click when opening a port or a scraper pool checks for IP/DNS leaks, confirms the fingerprint spoof actually reaches the target, and reports whether the upstream proxy supports UDP.
    • View profile: inspect the exact identity a port presents — User-Agent, TLS composition, and the expected JA3.
    • Import fingerprint: capture a real browser's fingerprint and apply it to a port, or save it under a name and reuse it later by name.
  66. 1.0.4Flexible routing

    • Domain Routing rules: a dedicated tab to send chosen domains or exact hosts through a different proxy, gateway, or chain — each rule with its own spoofing settings, or none.
    • Profiles counter now breaks down by OS, browser, and browser version.
  67. 1.0.3Smarter caching

    • Two new hard-cache modes: 'media only' and 'auto-warm'.
    • The product version is now shown in the dashboard.
  68. 1.0.2Productivity features

    • Idle-timeout control: set it globally by clicking, or a custom timeout / 'never' per port.
    • Profile sources: curated database, on-the-fly generation, or random.
    • Header spoofing: rewrite outdated request headers to match the current browser (recommended for scrapers).
    • Port presets: named sets of ports with their settings and folders, preserved across updates.
    • Scraper batch mode: a pool of proxy ports over a range fed by a rotating upstream list, with automatic fingerprint & proxy rotation, self-healing, and one-click export of the open ports as a proxy list.
  69. 1.0.1Onboarding & installers

    • Simplified first-run setup (guided onboarding, choose your own password).
    • A single Windows app with a system-tray icon and product logo — no console window.
    • Localized installer (EN/RU/ZH) with one-click root-certificate install.
    • In-place updates: detects an existing version and updates it without resetting your license or settings.
    • Cleaner logs.
  70. 1.0.0Initial release

    • First public release of BlankTrail Proxy.
  71. 1.1.1 – 1.1.2Reliability & resilience

    • The app handles brief internet interruptions more gracefully and starts up more reliably.