# Fix no internet with a Mullvad exit node

**TL;DR:** Turn OFF the "override DNS servers" option in the admin console and enable `--exit-node-allow-lan-access`. The DNS override is only needed on ancient Tailscale versions; on current ones it breaks Mullvad exit nodes.

## The error

```text
No internet connectivity when using Mullvad as exit node
```

`tailscale status` shows the Mullvad node as `active; exit node`, but nothing loads. Turning the exit node off fixes it instantly.

## Fix it

### 1. Disable the DNS override

In the admin console, open DNS settings and turn OFF "override DNS servers" (override local DNS).

Expected: no more forced DNS override for the tailnet.

### 2. Allow LAN access on the client

```
sudo tailscale up --exit-node-allow-lan-access
```

(re-run with whatever other flags you normally use).

Expected: local network still reachable while on the exit node.

### 3. Check the Mullvad server itself

Look up the specific server (e.g. ca-tor-wg-001) on the Mullvad server list and confirm it is online. Try a different Mullvad exit node if yours is down.

Expected: `tailscale exit-node list` shows candidates; pick a healthy one.

### 4. Re-test

```
tailscale status
curl -sI https://example.com | head -1
```

Expected: status shows the exit node active, and the curl returns HTTP/2 200 through it.

## When this applies

- Internet dies only when a Mullvad exit node is selected
- `tailscale status` shows the exit node as active
- You followed old guides that said to override DNS for Mullvad

## When it does not apply

- Self-hosted exit nodes broken (different checklist: IP forwarding, firewall)
- No exit node works at all (client or tailnet problem)
- The Mullvad node is down for everyone (pick another server)

## Tool compatibility

Tailscale 1.5x and newer with the Mullvad integration. The DNS-override advice changed across versions; current clients do not need it.

## Variant phrasings

### Timeouts opening connections "to node" via the Mullvad peer

The log form: `open-conn-track: timeout opening (TCP ... => 1.1.1.1:443) to node`. Same fix.

## Why it happens

Old docs told users to override DNS when using Mullvad exit nodes. Current Tailscale handles DNS through the exit node correctly on its own, and the forced override conflicts with it, so name resolution (and everything after it) dies.

## Edge cases

- **Docker on NixOS:** one reporter needed the host's routing features set to client mode and the container on host networking for exit-node traffic to flow. Container networking adds its own layer.
- **Still broken:** re-read the current Mullvad exit-node docs page; the recommended settings have changed more than once.
- **Per-node flakiness:** Mullvad servers do go down. Rule out the server before rebuilding your config.