Skip to content

DNS and IPv6 ​

For iPhone / iPad.

Start with defaults ​

Change Settings → DNS only for a specific need, such as private domains, a chosen resolver or a reproducible lookup failure.

Custom DNS accepts the formats listed in the interface: plain IP, DoH, DoH3, DoQ, DoT and TCP. Separate multiple servers with commas; leave the field empty for automatic defaults. This setting serves lookups outside the tunnel and related cases, not necessarily every DNS request.

Add a domain-specific DNS rule ​

Add a domain-specific DNS rule
Chinese simulated interface with fictional data · Click to view full size
  1. Open Settings → DNS → Add DNS Rule.
  2. Choose Exact, Suffix or Wildcard and enter a domain.
  3. Choose Addresses, Alias, Split DNS or Always Real IP.
  4. Save and order rules; the first match wins.
  5. Make a new request and inspect the DNS result.

For example, send your private company domain to a reachable company resolver rather than sending all public names there. Check the route to that resolver first.

IPv6 ​

Inspect Settings → IPv6. Device networking, the node and the destination all affect availability. Compare one change at a time, then restore what you need.

Modules can contribute DNS settings too. Check module order when results differ from expectations. Avoid changing DNS, nodes and routing simultaneously.

Example: send only an internal domain to company DNS ​

Suppose you own corp.example.com and the company resolver is reachable from the current network:

  1. Add a suffix match for corp.example.com with the split-DNS action.
  2. Enter the company's actual resolver. The illustration's 192.0.2.53 is a documentation address, not a usable service.
  3. Enable and save it before any broader rule that would match first.
  4. Request a real internal hostname, verify its answer, then check VPN, routing or subnet permissions needed to reach that address.

A DNS answer does not establish a route to its address. Alias and address-record settings cannot replace network connectivity.

SymptomNext step
Every domain failsCheck resolver reachability and current network; revert the recent change for comparison.
Only internal domains failCheck match type, order, company DNS and company-network access.
Correct address but failed connectionCheck routing, node, IPv4/IPv6 and destination port.
Unexpected rule behaviorCheck network-profile overrides and module-provided DNS settings.

Features checked: 29 September 2026 · One topic per page