⚠️ iOS 27 / iPadOS 27: "Connectivity Assist" bypasses your local DNS #11473
Pinned
hagezi
announced in
Announcements
Replies: 3 comments 6 replies
2 replies
|
What about having tailscale(selfhosted headscale specifically) routing all the traffic to your local dns? It would work on either Wifi or Cellular |
2 replies
|
Perhaps thou mightst consider letting https://dnsleaktest.com wear thy mantle, where https://dnscheck.tools now rests? |
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Status: confirmed on the final release (iOS 27.0, released 14 September 2026)
Who this affects: anyone filtering DNS locally (Pi-hole, AdGuard Home, router DNS, any resolver handed out by DHCP)
Can blocklists fix it? No!
What's going on
iOS 27 renamed the old Wi-Fi Assist feature to Connectivity Assist and moved it from
Settings > Cellular to Settings > Wi-Fi. It's on by default, also after you update from
iOS 26.
The old feature only switched to cellular when your Wi-Fi was struggling. The new one uses cellular
in addition to Wi-Fi. That means your iPhone talks to your carrier's DNS servers and to the DNS
server from your router at the same time, while you're on Wi-Fi.
So some of your DNS queries never reach your local resolver. They go straight out over cellular to
your carrier instead. Blocked domains resolve, ads show up again, and you won't find anything in
your query log, because the query never got there.
What the tests show
Take a close look at the third row. An always-on encrypted DNS profile does stop the leak, but it
stops it by taking your local resolver out of the picture. If your filtering runs on a Pi-hole or
AdGuard Home in your network, that's not really a fix. You just swapped one bypass for another.
And look at the split tunnel row too, because that's the workaround most people try first. Routing
just your DNS traffic home through WireGuard or Tailscale does not help. The queries that go out
over cellular never enter the tunnel, so a rule that only catches DNS inside the tunnel never sees
them. Only a full tunnel catches everything.
How to check your own device
Open https://dnscheck.tools on your iPhone and look at which resolvers show up. If you see
servers from your mobile carrier while you're on Wi-Fi, you're affected. Turn Connectivity Assist
off, reload the page, and compare.
What you can do
Turn Connectivity Assist off (easiest)
There are two switches and both of them work:
that one network only.
Tested on the final release:
The leak only happens when both are on, so either switch is enough to stop it. However, it is recommended that you turn off the global switch.
All reactions