DNS problems often appear as working nodes with failing domains, destinations selecting the wrong rule, or test pages showing an unexpected DNS server. Keep one nameserver/fallback setup and retest. If the domain resolves correctly but still will not open, inspect rules and nodes instead of adding more DNS upstreams.
Who is resolving the domain: the system, browser, or Clash?
Disable secure DNS in the browser, then compare the system lookup, Clash logs, and server shown by a test page for the same domain to identify where the request went.
- Is Clash DNS enabled?
- Does system DNS still point to the ISP or router?
- Does the browser enable independent secure DNS?
- Do the logs show lookup failed, SERVFAIL, or timeout?
Standardize DNS upstreams and check rule matching again
- Disable independent browser DoH first and confirm that the request enters Clash DNS(See DNS documentation)
- Inspect nameserver, fallback, and nameserver-policy configuration
- Use the connection list to confirm the domain and final policy
- If the failure occurs only under TUN, inspect TUN DNS hijacking and routing(See TUN FAQ)
A DNS leak test reflects only the test environment and is not a complete privacy guarantee
Incorrect DNS affects rule-based routing and node connections
Enterprise networks may forcefully intercept or replace DNS
