## TL;DR
Confirm the VPN client is using the corporate DNS servers (nslookup will show which server answered), then check the DNS suffix search list includes the internal domain. If the home router is answering, DNS is leaking outside the tunnel and the client must be set to force DNS through the tunnel.

## The error
```text
nslookup intranet: server can't find intranet: NXDOMAIN (while on VPN)
```

## Steps
1. Run `nslookup internalhostname` and note which server answered. Expected: the corporate DNS server. If the home router (192.168.x.1) answered, DNS is leaking.
2. Check the VPN client's DNS settings: it must push the corporate DNS servers on connect. Expected: corporate servers listed first in the adapter settings.
3. Check the DNS suffix search list includes the internal domain (e.g. corp.example.com). Expected: present. Without it, short names like "intranet" never resolve.
4. Test the FQDN: `nslookup intranet.corp.example.com`. Expected: resolves. If FQDN works but short name does not, it is purely a suffix issue.
5. If DNS still leaks, enable "force all DNS through tunnel" (or the client's equivalent) and reconnect. Expected: corporate DNS answers everything. Some clients need this explicitly.

## When to use
- Internal names fail over VPN, IPs work
- Short names fail but FQDNs work

## When not to use
- Nothing resolves, internal or external (broader DNS/network issue)
- VPN not connected

## Compatibility
- Any VPN client; Windows/macOS DNS settings

## Variants
### Split-DNS configured intentionally
Some orgs resolve only corp domains internally; confirm the intended behavior before "fixing" it.
### Works for some users only
Compare client versions and profiles; the DNS push settings differ.

## Why it happens
Name resolution follows the configured DNS servers and suffix list, not the tunnel. The tunnel carries packets, but if the client asks the wrong server, internal names do not exist as far as the client knows.

## Edge cases
- Browsers with secure DNS (DoH) bypass the VPN DNS entirely; disable DoH on managed devices or allowlist the behavior.
- `ipconfig /flushdns` after fixing settings to clear stale negative entries.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ccNAtH3a0jBYhR7RA6G71w
