Users of Tailscale and Mullvad VPN are experiencing DNS leaks when using the two services in conjunction [1].

This issue threatens the privacy and security of users who rely on these tools to mask their network activity. When a DNS leak occurs, requests that should remain private or routed through a specific tunnel are instead exposed to the VPN provider's servers [1].

The problem has been reported on GitHub, where users described DNS requests being routed through Mullvad's servers rather than the user's intended network [1]. This behavior suggests a configuration issue or a potential vulnerability within the routing logic when Tailscale is active alongside the VPN.

Some users have encountered these issues while utilizing Tailscale Funnels to manage home network access [2]. For some, these tools are essential for remote management of personal hardware. One user said, "I can log into them whenever I want to work on a DIY project" [2].

However, the current routing instability complicates the experience for those who operate home labs. The same user said, "accessing my home lab setup becomes rather troublesome whenever I need to travel" [2].

Tailscale and Mullvad have not yet provided a definitive patch for the leak. Users are currently monitoring GitHub issue threads to track potential fixes and workarounds for the routing conflict [1].

DNS requests being routed through Mullvad's servers rather than the user's intended network

DNS leaks undermine the core value proposition of a VPN by revealing the domains a user visits, even if the traffic itself is encrypted. For Tailscale users—who often manage sensitive internal infrastructure and 'home labs'—this routing failure creates a security gap where internal network queries may be exposed to an external provider.