Your network 5 MIN READ
DNS & server addresses
Choose how names resolve inside the VPN, and separately how WireFuse finds a changing server endpoint.
In the appProfiles → Profile details → Edit → DNS / Server DNS / DDNS
Contents
Browse all guides →Two settings, two jobs
Tunnel DNS resolves names for your VPN connection. Server DNS / DDNS resolves the VPN server’s own endpoint before connecting and checks that address again while connected.
These settings are separate. Choosing a DNS service for browsing does not automatically select the resolver used to find the VPN server.
Choose tunnel DNS
Disconnect, open the profile editor and select the DNS mode you want to use. Supply valid details for the chosen resolver. Save, then reconnect so the tunnel uses the updated settings.
Custom tunnel DNS applies while the VPN is connected. If the selected custom service fails, WireFuse does not deliberately substitute system DNS. Check that service’s address and reachability before trying again.
This describes WireFuse’s resolver policy; it is not a guarantee about every request generated by tvOS or other apps.
Refresh a changing server address
Open Server DNS / DDNS in the profile editor. You can use system DNS or choose a supported encrypted resolver. Custom resolver settings let you provide its address and bootstrap IPs.
| Field | Meaning |
|---|---|
| Resolver URL or name | A full HTTPS URL for DoH, or a server name for DoT |
| Bootstrap IP addresses | IP addresses used to reach the resolver; separate multiple values with commas |
| Port | Blank uses 443 for DoH or 853 for DoT |
| Check interval | Minutes between regular checks; blank uses 30, allowed range 1–1440 |
| Address types | IPv4 and IPv6, IPv4 only, or IPv6 only for the endpoint |
The resolver certificate must be valid. When an encrypted resolver is selected, WireFuse does not silently switch these queries to system DNS. Endpoint lookups can travel outside the VPN because they are needed to find the VPN server itself.
What happens if a refresh fails?
Failed checks keep the last server address. Sleep and network recovery pause regular checks. Do not assume every address change is detected immediately.
Choosing IPv6-only endpoint resolution requires a compatible network and server. The address-family setting does not change the traffic routes inside your VPN.
Check the result
For a tunnel DNS check, open Settings → Diagnostics → DNS check while connected. It looks up example.com; it does not identify the resolver or test for leaks. A cached answer can be used.
If names fail but the server is verified, check tunnel DNS. If the server’s hostname cannot be resolved before connecting, inspect Server DNS / DDNS and the underlying network instead.
Still stuck? Contact support.