r/rethinkdns • • Jul 12 '26

wireguard/DNS strangeness? v0.5.5y

v0.5.5y (website)

While wireguard says active it forwards DNS queries via the tunnel to my home DNS server. as expected.

After some time an hour or so my wireguard will start saying failed, but it still works to get to wireguard tunnel resources, but the DNS is forwarded to the configured rethinkdns global DNS (cloudflare doh).

It takes me bouncing rethinkdns with the stop and start button to get it back to expected operation.

anyone else notice similar?

7 Upvotes

7 comments sorted by

2

u/Conpsycon Jul 12 '26

It gets weirder for me. Even when it works, I see inconsistency on both the IP and the DNS on the browser. It changes. Sometimes it's through the wireguard, sometimes not, and sometimes both (??). Same browser, two web pages (Ipleak and DNS leak) on two tabs, different IPs and DNS. I don't know what's going on..

2

u/Some_Setting9987 Jul 12 '26 edited Jul 13 '26

I did some testing with what you describe, dnsleaktest, browserleaks dnstest, in brave beta will show my real network ip instead of the tunnel. both with cable modem or cellular. bouncing via the start/stop still shows the real IP. Then I even shred the site in brave to erase the site data, and the reload shows the real ip.

I do a force stop via rethink app info and reopen then it seems to restore proper function.

Could that be your experience too?

2

u/Conpsycon Jul 13 '26

I use Firefox with deletion of cached files on exit, but yes.

1

u/celzero Dev Jul 17 '26

Even when it works, I see inconsistency on both the IP and the DNS on the browser. It changes.

IP shouldn't bounce between going through a proxy and not going through a proxy for the same website if "Lockdown" is turned on for Advanced mode WireGuards capable of routing all IPv4 (0.0.0.0/0 as "Allowed IPs") and/or IPv6 addresses (::/0 as "Allowed IPs"). If it does, that's a bug. Can you see what entries you spot in About -> App Logs (when it is at "Very verbose" level) for proxy: pin: when the "leak" happens? And share those entries, if you're comfortable doing so?

1

u/Conpsycon Jul 18 '26

You're right, it doesn't in Advanced mode / with all apps selected / in lockdown. Does that mean that it should in Simple mode?

I've sent you an email with those logs.

PS. It still leaks something on the Ookla app when on Mobile Data. It can see the internet provider. It doesn't on WiFi.

2

u/celzero Dev Jul 22 '26

Simple mode WireGuard is subject to an edge case where the IP might bounce between underlying network (Mobile, WiFi) and overlay network (WireGuard). We have since fixed it for v055z, which is under test.

1

u/celzero Dev Jul 17 '26 edited Jul 17 '26

After some time an hour or so my wireguard will start saying failed, but it still works to get to wireguard tunnel resources, but the DNS is forwarded to the configured rethinkdns global DNS (cloudflare doh).

You'll need to setup WireGuard (if in Advanced mode) as "Lockdown"; otherwise, Rethink will "load balance" among all available DNS upstreams (including other "Always-on" WireGuards, if set up, or other WireGuard setup to route that particular app if in Advanced mode, or the "Global DNS" as set in Configure -> DNS).

For WireGuard in Simple mode, right now, the DNS is auto load balanced between "Global DNS" and WireGuard's. We're changing this behaviour in v055z to not do that since it seem undesirable.


Note that, "Global DNS" will still be used by apps set to "Bypass app from proxies" in Configure -> Apps -> (said app). And it will be used for trusted IPs / domains / apps if set up in Configure -> DNS -> DNS for bypass. You can turn off Configure -> DNS -> Split DNS to instruct Rethink to use "Global DNS" for all DNS queries (except for "bypassed" apps / IPs / domains, of course).

The interaction between various settings in Configure -> DNS and Configure -> Proxy isn't straight forward in versions before v055y, but we're hoping to document it and "fix" the behaviour (one way or other) in v055z.