dns not resolving internal hostnames over vpn"
Fixes internal DNS resolution failures over VPN. Covers DNS server assignment, suffix search, and leak issues. Use when internal names fail but IPs work over VPN. Not for public DNS failures.
TL;DR
Confirm the VPN client is using the corporate DNS servers (nslookup will show which server answered), then check the DNS suffix search list includes the internal domain. If the home router is answering, DNS is leaking outside the tunnel and the client must be set to force DNS through the tunnel.
The error
nslookup intranet: server can't find intranet: NXDOMAIN (while on VPN)Steps
- Run
nslookup internalhostnameand note which server answered. Expected: the corporate DNS server. If the home router (192.168.x.1) answered, DNS is leaking. - Check the VPN client's DNS settings: it must push the corporate DNS servers on connect. Expected: corporate servers listed first in the adapter settings.
- Check the DNS suffix search list includes the internal domain (e.g. corp.example.com). Expected: present. Without it, short names like "intranet" never resolve.
- Test the FQDN:
nslookup intranet.corp.example.com. Expected: resolves. If FQDN works but short name does not, it is purely a suffix issue. - If DNS still leaks, enable "force all DNS through tunnel" (or the client's equivalent) and reconnect. Expected: corporate DNS answers everything. Some clients need this explicitly.
When to use
- Internal names fail over VPN, IPs work
- Short names fail but FQDNs work
When not to use
- Nothing resolves, internal or external (broader DNS/network issue)
- VPN not connected
Compatibility
- Any VPN client; Windows/macOS DNS settings
Variants
Split-DNS configured intentionally
Some orgs resolve only corp domains internally; confirm the intended behavior before "fixing" it.
Works for some users only
Compare client versions and profiles; the DNS push settings differ.
Why it happens
Name resolution follows the configured DNS servers and suffix list, not the tunnel. The tunnel carries packets, but if the client asks the wrong server, internal names do not exist as far as the client knows.
Edge cases
- Browsers with secure DNS (DoH) bypass the VPN DNS entirely; disable DoH on managed devices or allowlist the behavior.
ipconfig /flushdnsafter fixing settings to clear stale negative entries.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ccNAtH3a0jBYhR7RA6G71w
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.