[kwlug-disc] Systemd resolv issue ...

Khalid Baheyeldin kb at 2bits.com
Wed Feb 11 16:40:56 EST 2026


Thanks for the clues ...

Here are the active interfaces:

This is an Ethernet port:
Note that it says DNS Domain is lan.
Perhaps that means queries to foo.lan only will go through it?

Link 3 (enp3s0)
   Current Scopes: DNS
        Protocols: +DefaultRoute -LLMNR -mDNS -DNSOverTLS
DNSSEC=no/unsupported
Current DNS Server: 192.168.0.1
      DNS Servers: 192.168.0.1
       DNS Domain: lan

The Wireguard interface on the other hand has ~. as below:

Link 12 (wg0)
   Current Scopes: DNS
        Protocols: +DefaultRoute -LLMNR -mDNS -DNSOverTLS
DNSSEC=no/unsupported
Current DNS Server: 10.10.0.1
      DNS Servers: 10.10.0.1
       DNS Domain: ~.
Both are default routes, but the domain is what sticks out.

Is the ~. a wildcard?
If it is, does that mean "everything"?i.e. that all DNS queries will go
through the VPN?
Why did Wireguard force resolveconf to use the -x flag?

I don't want the VPN to be the default DNS.
I want all DNS queries to go through enps30, and only domains ending with
.priv to go through wg0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kwlug.org/pipermail/kwlug-disc_kwlug.org/attachments/20260211/0f9e71ec/attachment-0001.htm>


More information about the kwlug-disc mailing list