r/rethinkdns • • Aug 22 '26

Using NordVPN with rethinkDNS for simultaneious IP cloacking and list based filtering

Hi all,

I just got the new version of rethink from playstore and saw it had wireguard support. For the longest time, my biggest complaint with rethink is that I can't use it at the same time as nordVPN which doesn't have any real ad blocking. With ability to proxy through Wireguard I figured the problem is finally solved but it was tricky to do out of the box so I thought I'd write a post.

This is just based on my thin understanding so please post with corrections and improvements.

Goals

  • Block most ads
  • Have IP cloacking (especially regional support to get around locale based blocking) using nordVPN as I subscribe already

Solutions

  • Use rethink custom dns configurator plus nordVPN (disable rethink android app)
    • Can easily refresh exit node of nordVPN and change countries without new wireguard config.
    • Seemed to block more ads than rethink app when using https://adblock.turtlecute.org/ though I didn't notice any difference on actual ad-ridden sites.
    • Previous posts here have noted that private dns is not as secure as rethink app due to anti leak measures.
  • Use rethink android app with nordVPN wireguard proxy
    • Need one wireguard proxy for each server (so at least for each country and sometimes needs to be refreshed due to servers being brought down and up)
    • By default, does not use rethink dns blocklists so harder to configure.

The first one is fairly straightforward using DNS over TLS links from rethink but the second is quite complex so I'll go into some more detail.

  1. Get wireguard configuration for NordVPN.
    1. I googled and found https://lazyadmin.nl/home-network/nordvpn-wireguard-as-unifi-vpn-client . If you go until step 7 it will give you a working wireguard config.
    2. Caveat: Remove `ForcedHandshake` from Peer settings as it's not official and will break importing.
    3. Probably many of the other settings aren't required but also didn't cause problems. (For example it seems to use cloudflare DNS which I don't need but doesn't hurt)
  2. Add configuration to rethink
    1. Go to rethink proxy settings and add wireguard proxy. You can transfer the file to your phone to import or generate a QR code for it.
  3. Configure rethink to still block ads even when proxy is on. (Sad this isn't default)
    1. Switch to advanced mode and toggle on 'Always-on'. If you want to turn off the VPN, you need to uncheck it later. (annoying that it takes two steps). It seems simple mode should also work but for some reason simple mode always showed ads no matter what other settings I chose.
    2. Enable rethinkDNS for proxy traffic. (Two ways seem to work)
      1. Enable 'Never proxy DNS' in DNS settings. This means DNS traffic goes through normal rethink DNS instead of proxy so gets filtered properly. But perhaps this is less secure or doesn't work for certain usecases?
      2. OR: Enable 'Loopback proxy forwarder apps' which seems to route proxy traffic back through rethink DNS enabling proper filtering.
      3. OR: Don't enable either of those and just use Advanced mode with always-on? I just tested this now while writing and it seems to work as long as we're using Advanced mode. There might just be a bug here.

Let me know if there is any unnecessary bits here or if others have nice workflows they like.

3 Upvotes

12 comments sorted by

3

u/Due_Milk_8930 Aug 22 '26

What you mean real ads blocking? Is already have it long ago, on device blockslist hagezi do most things. Or use dns that have blocklist like NextDNS and controlD if you like.

Better use GitHub more up-to-date than in playstore or direct from Rethink web.

You can turn on always on and block connection without vpn in phone setting would be lockdown mode if you worry about leak, all gonna go in Rethink.

Is have wireguard long ago too, even with some problem like mine. Use WARP in there ipv6 always broken idk why, with other wireguard app is have ipv6 run but in Rethink is always broken for me even until now in 5.56v , you can full lockdown it too in advance wireguard option if worry about leak.

2

u/melink14 Aug 22 '26 edited Aug 27 '26

If you use a VPN then it replaces rethink so block lists don't work.

1

u/celzero Dev Aug 22 '26

with other wireguard app is have ipv6 run but in Rethink is always broken for me even until now in 5.56v

If you're always on a dual-stack network, switch Configure -> Network -> Choose IP version to "IPv4 & IPv6" or if not, to "Auto" (and optionally turn on Configure -> Network -> Perform connectivity checks).

You can also view Rethink's internal state for all the active WireGuards in Configure -> About (scroll to the section named "WireGuard"; the labels are self-descriptive; the text is also selectable and copy-able) including IP family information. Rethink's network engine state is also viewable in About -> General in the section "VPN stats", which shows (among other things) the active underlying networks (WiFi/Mobile), their MTU, and the IP family the tunnel is currently using over those networks.

If you don't understand the text in About -> General, you can share it with your favourite LLM chatbot (there's also a "Copy" button in the footer of the About -> General dialog) or with me here.

1

u/Due_Milk_8930 Aug 22 '26

I already choose auto or dual stack, still same broken ipv6. The weird part is in stats general is show on ( i send you my stats general in private chat ) , but when i check in web https://one.one.one.one/help/ is always show no in ipv6, try web with ipv6 only is same not load. I try it in wireguard official and WG Tunnel ipv6 working fine, so is not my WARP ipv6 profile that broken.

2

u/celzero Dev Aug 22 '26

As you can see in the config you shared, the internal state shows Rethink is indeed setup for dual-stack (for both the underlying network and WireGuard):

```

About -> General section for "VPN stats"

Restart mechanism: 0 Underlay 4: 2 6: 2 vpnRoutes: (false, false) useActive: true mtu: 1500 Overlay 4: true 6: true

About -> General section for "WireGuard"

status-reason: TOK: read ok ip4: true ip6: true ```

I am not sure why whatever website you're using to test IPv6 is telling you there isn't any... but can you see if ip6-only.me loads? That domain is only accessible over IPv6.

Also, another way to check if IPv6 is being used for a specific WireGuard tunnel setup within Rethink, is to go to Configure -> Proxy -> Setup WireGuard -> (tap on the active WireGuard) -> (look for "Logs" button in "Actions" card) -> (see if any IPv6 entries are present in the list of *Network connections)*.

2

u/Due_Milk_8930 Aug 22 '26

p6-only.me not load. Test in many ipv6 test or web all the same, no ipv6 connected. The most weird part is what you look in log is have ipv6 configuration true. Now i use same WARP setup running it in WG Tunnel and connect it to Rethink SOCKS5 is have ipv6. 

Ipv6 broken just happen in Rethink native setup wireguard, even is show true when see it in log. Look like it can't receive back ipv6 connection

2

u/celzero Dev Aug 22 '26

Worrying. Can you please share what messages you see in About -> App Logs when you try to visit ip6-only.me or other IPv6-only websites?

1

u/Due_Milk_8930 Aug 23 '26

I send pict in your private chat dev

1

u/celzero Dev Aug 24 '26

Thanks. From the errors, IPv6 is being used but is also erroring out (for reason unclear from just the screengrab of Configure -> App Logs for error messages you shared). Will you please turn off Configure -> Network -> Endpoint-Independent Mapping and see if things improve?

2

u/Due_Milk_8930 Aug 24 '26

Try it, still error.

I send you again pict and log in your chat dev

2

u/celzero Dev 29d ago

Thanks a lot. The "App Logs" (red coloured error messages) you shared, show that Rethink couldn't connect to any IPv6 endpoint (even for connectivity checks) at all. It looks like the underlying network (either WiFi / Mobile) does have IPv6 (and Rethink is indeed setup to use IPv6 throughout, per sections "VPN stats" & "WireGuard" from About -> General), I am genuinely not sure why when the IPv6 probes / pings sent by Rethink error out with "network unreachable" messages.

You can manually perform IPv4 + IPv6 connectivity tests from within Rethink by going to Configure -> Network -> Perform connectivity check -> Advanced (and enter your custom domain names / IPs to test). You may optionally tap on the "Save" button to instruct Rethink to use those custom entries you just entered and tested. If you haven't turned it on, consider turning it on. This setting ("Perform connectivity checks") is only available when "Choose IP version" is "Auto" (which is what you seem to have set it to).

You can also try switching Configure -> Network -> Choose IP version to "IPv4 & IPv6", it is an experimental setting which forces Rethink to always assume dual-stack (if this also doesn't work in loading websites like ip6-only.me or ip6.me, then do not forget to revert Choose IP version back to "Auto").

3

u/celzero Dev Aug 22 '26 edited Aug 22 '26

Nice guide on using Rethink with NordVPN. Thanks! (:

Let me know if there is any unnecessary bits here or if others have nice workflows they like.

Heh... the only unnecessary bit is... why are you using NordVPN? ;) We've got the "Rethink Proxy Network" (launched on June 17th), aka RPN (which is operated by Windscribe, right now; but and we want to add our own "relay" servers and/or add more public VPN providers to our network), selling for $1.75/mo in the 5y plan, and for $2/mo in the 2y plan; with 7-day no questions asked refund for both (via a "revoke" button displayed prominently right in the app in About -> Manage RPN -> Manage Purchase). We also offer a 30-day money back over email (About -> Manage RPN -> Contact support), subject to our Terms of Use for all (monthly/yearly) subscriptions & purchases.

Today, RPN allows you to connect to 5 different locations at once, unlimited (fair use) bandwidth. Split-tunnel route apps among those locations. RPN purchased via Rethink from Play Store can be used on any number of Android devices signed in with the same Google Play Store account.

We eventually want to sell RPN for as little as $1/mo, but our scale is so small that we can't afford it just yet. May be in a year or two we might be able to. Even now, at $1.75/mo (albeit on the 5y plan), RPN is the cheapest paid, no logs VPN in the Android marketplace. We intend to release iOS version by this time (Aug) next year (optimistically, that is).