HeadlinesBriefing favicon HeadlinesBriefing.com

Tailscale with Mullvad Leaks DNS

Hacker News •
×

Tailscale users who pair the VPN with Mullvad can unknowingly expose their DNS traffic, creating a privacy risk that many overlook. The leak occurs because Tailscale’s default routing pushes all queries through the local network unless the user explicitly sets a DNS server. When Mullvad’s DNS is not enforced, DNS requests can still go to the ISP’s resolver, leaking the user’s true domain queries.

The fix is straightforward: manually configure Tailscale to use Mullvad’s DNS servers. In the Tailscale admin console, add the Mullvad DNS IPs (e.g., 119.29.29.29 and 119.29.29.30) under the DNS settings for each subnet. This ensures that all traffic, including DNS, is routed through the secure tunnel. If you prefer a per-device approach, the Tailscale client on each machine also allows you to set custom DNS servers.

After reconfiguring, verify the protection by running a DNS leak test or monitoring the logs. A successful test shows no queries to the ISP’s resolver. Regularly check for updates, as both Tailscale and Mullvad occasionally release changes that might affect DNS handling.

By taking these steps, users can maintain the anonymity that both services promise and avoid unintentional DNS exposure.