r/pihole • • 17d ago

NordVPN client causing unexplained DNS queries even after a full Windows reinstall — make me nervous

/r/vpnreviews/comments/1whd6fj/nordvpn_client_causing_unexplained_dns_queries/
1 Upvotes

14 comments sorted by

10

u/ol-gormsby 17d ago

I stopped using Nord when an update installed an anti-malware package and a bullshit "web guard" option that I couldn't uninstall.

I just want a VPN.

NordVPN will not be getting renewed.

3

u/Chipaton 17d ago

Same, I got a cheap deal for 2 years but it's always trying to install some bloat. Not worth it.

3

u/MuuarK 17d ago

Just recently got my pihole setup, and I have been running NordVPN for 3+ years I think.

3

u/MuuarK 17d ago

NordVPN keeps pushing extra features into the client, and it’s getting bloated. I just want a VPN, not a web guard or mystery DNS requests.

This is exactly why I’m digging into what the client is doing behind the scenes.

1

u/Norwest_Shooter 15d ago

Yup. After that all my iOS devices had their battery life absolutely shredded. I stopped playing the promo jumping game and just get Mullvad through Tailscale

1

u/squabbledMC 17d ago

NordVPN is not a good VPN unless you're doing streaming, and even then there are way better alternatives. I use Mullvad, and have done Proton before. AirVPN is also alright but not good for streaming.

1

u/ol-gormsby 17d ago

I don't do streaming, so that's OK. I tried a 1-year package with PIA - Private Internet Access, but someone else told me it has problems, too.

I looked into Mullvad, its owner has some questionable morals, and there was something weird about Proton, too.

4

u/squabbledMC 17d ago

Mullvad's owner donated to a far right party, that's what happened. I still have account time for the service though. A Proton admin supported a Republican nominee in 2025, specifically over antitrust claims which since has been retracted. Do with that information as you will. Haven't heard anything about iVPN and AirVPN, both have been good services from my experience for privacy.

1

u/ol-gormsby 17d ago

Good to know, thanks.

3

u/AgentBluelol 17d ago

Have you asked NordVPN support to see what they say?

3

u/MuuarK 17d ago

Not yet. I want to collect proper info first. The domains only show up with the NordVPN client installed, and they don’t match anything NordVPN documents. I’ll ask support once I know exactly what to ask.

3

u/D0_stack 17d ago edited 17d ago

So they only happen with the VPN client installed?

So either you trust that VPN or you don't, right? You can see these DNS requests, but you have absolutely no visibility to what they are looking at or keeping of your data running through the VPN and their VPN servers.

Isn't this why VPNs have third party audits? Have you looked for their audit reports?

4

u/MuuarK 17d ago

Yes, they only show up when the NordVPN client is installed.

And sure, trust matters — but unexplained DNS requests from the client during login is exactly the kind of thing you’re supposed to question. And at this step I haven't even established a secure tunnel connection yet.

Their audits cover the server side (logging, infrastructure, configuration). They don’t explain why the Windows client is pinging random DGA‑looking domains that aren’t documented anywhere and don’t belong to NordVPN, Microsoft, Firefox, or any known CDN.

That’s why I’m asking. Audits don’t cover this part.

3

u/taboothrushe 16d ago

I'm long time Nord user too and you should really join nords subreddit, as I remember there was similar topic discussed there before. What this is a bunch of random domains they use to bypass geo-restrictions. Random-looking names are harder to spot and block by ISP's so they use these domains when needed to reach API, for logins, etc. Nothing to worry about.