VPN client DNS overreach

Hi everyone! Recently purchased Slate AX router to bypass local restrictions. I want some websites to bypass Mullvad VPN Client tunnel for faster loading speeds, so I use VPN POLICIES BY DOMAIN.

However, I noticed that some excluded websites would rate-limit me and say that I visit them too many times. Tested IP by excluding whatismyip from the tunnel and shows my non-vpn location. I then headed to Mullvad page which also shows my non-VPN location; however I noticed that it still uses DNS from Mullvad even though it was excluded.

I have AdGuard Home enabled with some filters too. As of my understanding, AH upstream will be routed through VPN client and replaced with Mullvad's DNS of the current server. For some reason, it is also the case for excluded domains. :frowning:

Anyone?

If ADG is enabled, all DNSs are handled by ADG, including the excluded domains set on VPN policy (that list is not related to ADG).

he excluded domain are just go to WAN port instead of using the VPN port when establishing TCP/HTTP. But the DNS queries will go to the VPN port.

You mentioned that the VPN provider you are using is Mullvad.
According to our experience, Mullvad will hijack all DNS (port 53) traffic, no matter what DNS server you set up in VPN profile, router DNS, ADG DNS, clients network adapter DNS, their DNS (port 53) after arriving at Mullvad VPN server, it will be resolved by Mullvad DNS.

(Small test: The Surfshark also do so, but NordVPN won't.)

As for limiting traffic or speed, it should be related to the application server, web server, etc. , not our router interface.