DNS

Routing → DNS.

There are always two resolvers, and that is the point:

  • Through the tunnel answers for names that go through the proxy, and is asked through it;
  • Direct answers for names that go around the proxy.

One resolver for both is the classic leak: the DNS query would tell, outside the tunnel, where you are going.

Schemes: plain UDP (1.1.1.1), tcp://, tls:// (DoT), https:// (DoH), quic://, h3://, dhcp://, and local (direct only: ask the system). A typo is caught in the field, not at connect time.

Addresses chooses which records to ask for: both (IPv4 or IPv6 first) or one kind only. FakeIP speeds up connections through the proxy; it turns on separate resolver caches with it.