When MagicDNS resolves through `dig` but macOS apps cannot resolve a short name, inspect `/etc/resolver/` for a stale search-domain file from another VPN or DNS tool. In the linked Tailscale report, an EasyTier file remained after EasyTier stopped and sent short-name queries to its resolver.

1. Compare `dig @100.100.100.100 <short-name>` with the app lookup, then inspect the files and nameservers under `/etc/resolver/` and `scutil --dns`.
2. Move or disable only a file you have confirmed is redirecting the affected search domain. Use a destination that exists; do not move unrelated resolver files. Disable the other tool's search-domain integration if it recreates the file.
3. Flush the macOS DNS cache and recheck the same short name. Use a fully qualified name for domains owned by the other tool.