      My wg config has:

      DNS =

      AllowedIPs =

      DNS requests are still being sent through the tunnel even though it’s not in AllowedIPs, and even if it was, I don’t think it should go through the tunnel. If I wanted my dns to go through the tunnel I would configure the vpn server as the DNS, no?

      Are DNS always forced through the tunnel regardless of config settings?


      This software is amazing and much more stable compared to the official wg client.

      Thanks for your hard work.

      Vadim Smirnov

        Thank you for you warm words. You’re correct. When DNS settings are present in the Wireguard configuration file, all DNS requests are channeled through the tunnel to the specified DNS server, irrespective of the ‘AllowedIps’ setting. If DNS isn’t configured, then other filters, like ‘AllowedIps’, come into play.


          It’s working after I removed the DNS setting. DNS is no longer going through my tunnel.


          Good enough for me. Thank you again.




