Tailscale and "Block Non-VPN Traffic"

Here is where I got the info from:

Tailscale’s MagicDNS when enabled sets up 100.100.100.100 as a local DNS server that you can use to do reverse lookups.