All posts
GuidesJuly 31, 2026·6 min read

DNS Leaks, VPNs, and How Casper’s Cloak Handles Your Lookups

Learn how Casper's Cloak routes DNS through encrypted WireGuard, blocks trackers server-side, and handles bypass choices without leaking lookups.

By Casper's Cloak Security Team

Casper’s Cloak carries traffic through an encrypted WireGuard tunnel and resolves DNS on Casper’s servers, where server-side DNS ad and tracker blocking runs.

Why people worry about DNS leaks

A recent Hacker News signal observed a thread titled “Tailscale with Mullvad leaks your DNS.”

How Casper’s Cloak routes traffic and DNS

Casper’s Cloak is an AI-enhanced privacy and network-security platform for consumers and privacy-aware power users on iPhone, Android, and Mac. It is explicitly positioned as more than a VPN.

Under the hood, Casper:

  • Uses an encrypted WireGuard VPN tunnel via WireGuardKit / wireguard-go and native Network Extension on iOS and macOS to carry traffic
  • Routes DNS through Casper’s own servers, where DNS-level ad and tracker blocking runs server-side
  • Combines this with an on-device AI threat-detection layer that analyzes connections in real time

DNS-level ad and tracker blocking

Casper’s ad and tracker blocking is DNS-level and runs on managed VPN exit servers. When an app tries to contact an ad or tracker domain:

  • The DNS request goes through the encrypted WireGuard tunnel to Casper’s servers
  • Casper provides DNS-level filtering and blocking

This design means blocking decisions apply system-wide across apps.

AI threat detection on top of the tunnel

Casper adds an AI security layer on the device that includes:

  • Machine-learning threat detection
  • Real-time analysis of network connections
  • Zero-day phishing detection
  • Malware detection and blocking
  • Domain-reputation analysis and real-time threat classification

Smart Bypass, split tunneling, and user control

Casper gives you control over what goes through the tunnel:

  • Smart Bypass is a user-configured exclusion list. You can enable service presets and add custom domains or IP ranges that should be excluded from the VPN tunnel.
  • Split tunneling supports domain-based and IP-based exclusions through the same live path as Smart Bypass.

Both are user-driven. Casper does not automatically classify destinations as “trusted” or decide per flow what to bypass. When you exclude a banking domain, that destination leaves the encrypted tunnel and loses decoy cover.

Sensitive Site Detection and banking

Casper’s Sensitive Site Detection watches for certain categories when DNS remains inside the tunnel:

  • Banking
  • Healthcare
  • Government
  • Cryptocurrency

When it sees one of these, it:

  • Raises an in-app advisory
  • Automatically triggers decoy traffic (“Phantom Barriers”) to cover the visit

The tunnel itself does not get stronger or change routes. The only automatic response is decoy traffic, and the in-app advisory for banking explicitly recommends disconnecting from the VPN before accessing banking.

What this means in practice

For a privacy-aware user comparing tools after reading about DNS leaks:

  • Casper’s Cloak carries your traffic through an encrypted WireGuard tunnel
  • DNS is resolved on Casper’s servers, where DNS-level filtering blocks ad and tracker domains
  • An on-device AI layer analyzes connections in real time to detect phishing and malware
  • You control exclusions via Smart Bypass and split tunneling; when you exclude a banking domain, that destination leaves the encrypted tunnel and loses decoy cover

Casper is not just a VPN; it is a hybrid product combining on-device threat detection, server-side DNS/network filtering, and encrypted WireGuard routing.

Protect DNS Beyond the Browser

Casper's Cloak combines encrypted WireGuard routing, server-side DNS filtering, and on-device threat detection across iPhone, Android, and Mac.

Get Casper's Cloak