As you have figured out, trying to exclude services like this via domain is going to be a bit frustrating. Different domains can be used to serve different parts of their services which can lead to whats happening.

If your TV supports running a native surfshark app you can do split tunnelling whereby you can exclude certain apps from using the VPN. You can't really do split tunneling on the router as you would be forever trying to figure out the domains.

If possible it's best to just exclude or include the whole device via MAC address for simplicity.

Again, if you need the TV to only route certain TV apps and you can't install the surfshark VPN then the next best thing would be to purchase a Fire TV stick as that runs on android and has a surfshark app which can be installed to allow split tunneling.

1 Like