Skip to content

tun模式存在dns泄漏 #6454

Description

@PhoenixNil

完整性要求

  • 我读完了 issue 模板中的所有注释,确保填写符合要求。
  • 我保证阅读了文档,了解所有我编写的配置文件项的含义,而不是大量堆砌看似有用的选项或默认值。
  • 我提供了完整的配置文件和日志,而不是出于自己的判断只给出截取的部分。
  • 我搜索了 issues, 没有发现已提出的类似问题。
  • 问题在 Release 最新的版本上可以成功复现

描述

开启tun模式会出现dns泄漏的问题

重现方式

把v2rayN的config.json 文件复制到xray目录下面 用 .\xray.exe -c config.json 然后访问各种检测dns泄漏网站会出现dns泄漏的问题

Image

客户端配置

{
"log": {
"loglevel": "debug",
"dnsLog": true
},
"dns": {
"servers": [
{
"address": "223.5.5.5",
"domains": [
"geosite:cn",
"geosite:private"
],
"skipFallback": true
},
{
"address": "8.8.8.8"
}
],
"queryStrategy": "UseIPv4",
"disableCache": false
},
"inbounds": [
{
"tag": "tun-in",
"protocol": "tun",
"settings": {
"name": "xray0",
"mtu": 1500,
"gateway": [
"10.0.0.1/16",
"fc00::1/64"
],
"dns": [
"1.1.1.1",
"8.8.8.8"
],
"userLevel": 0,
"autoSystemRoutingTable": [
"0.0.0.0/0",
"::/0"
],
"autoOutboundsInterface": "auto"
},
"sniffing": {
"enabled": true,
"destOverride": [
"http",
"tls",
"quic"
]
}
},
{
"tag": "mixed-in",
"protocol": "socks",
"listen": "127.0.0.1",
"port": 16890,
"settings": {
"auth": "noauth",
"udp": true
}
}
],
"outbounds": [
{
"tag": "proxy",
"protocol": "shadowsocks",
"settings": {
"servers": [
{
"address": "",
"port": ,
"method": "2022-blake3-aes-128-gcm",
"password": ""
}
]
},
"streamSettings": {
"network": "tcp"
}
},
{
"tag": "direct",
"protocol": "freedom",
"settings": {}
},
{
"tag": "block",
"protocol": "blackhole",
"settings": {}
},
{
"tag": "dns-out",
"protocol": "dns"
}
],
"routing": {
"domainStrategy": "AsIs",
"rules": [
{
"type": "field",
"inboundTag": [
"tun-in"
],
"port": "53",
"outboundTag": "dns-out"
},
{
"type": "field",
"outboundTag": "direct",
"process": [
"self/",
"xray/"
]
},
{
"type": "field",
"outboundTag": "block",
"network": "udp",
"port": "443"
},
{
"type": "field",
"outboundTag": "proxy",
"domain": [
"geosite:google"
]
},
{
"type": "field",
"outboundTag": "direct",
"domain": [
"geosite:cn",
"geosite:private"
]
},
{
"type": "field",
"outboundTag": "direct",
"ip": [
"geoip:cn",
"geoip:private"
]
},
{
"type": "field",
"outboundTag": "proxy",
"network": "tcp,udp"
}
]
}
}

服务端配置

由于是机场无法提供

客户端日志

新建 文本文档.txt
太大超过65536个字符

服务端日志

机场节点无法提供

Activity

  1. Fangliding commented on Jul 8, 2026

    @Fangliding
    Member

    请自行关闭Windows的智能多宿主解析

  2. Meo597 commented on Jul 8, 2026

    @Meo597
    Collaborator
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient]
    "DisableSmartNameResolution"=dword:00000001
  3. RPRX commented on Jul 8, 2026

    @RPRX
    Member

    使用 Windows TUN 时有管理员权限,要不自动把“智能多宿主解析”给关了吧,@LjhAUMEM @yiguodev

  4. reopened this on Jul 8, 2026
  5. PhoenixNil commented on Jul 9, 2026

    @PhoenixNil
    ContributorAuthor

    Image 缓解无效 @Meo597

  6. PhoenixNil commented on Jul 9, 2026

    @PhoenixNil
    ContributorAuthor

    补充一下,我也试了同时禁用LLMNR 和关闭智能多宿主解析也没用

  7. yiguodev commented on Jul 9, 2026

    @yiguodev
    Collaborator

    目前可以确定的是裸核模式下这个问题很难解决,还是建议放弃吧。

    1. 目前已测试并验证 macOS 下无法解决。
    2. 根据上面的反馈来看,Windows 下同样无法解决。
    3. Linux 可通过 D-Bus 接管系统 DNS,未验证。
    4. 参考了其他社区(mihomo)的实现,无有效手段。
  8. mclovin-2k commented on Jul 9, 2026

    @mclovin-2k

    难道不是你分流的原因吗?
    你把 CN 的规则去掉,让所有流量都走 proxy 再测一次试试。

  9. PhoenixNil commented on Jul 9, 2026

    @PhoenixNil
    ContributorAuthor

    难道不是你分流的原因吗? 你把 CN 的规则去掉,让所有流量都走 proxy 再测一次试试。

    跟分流没多大关系…… 改成全局还是会漏

  10. mclovin-2k commented on Jul 9, 2026

    @mclovin-2k

    难道不是你分流的原因吗? 你把 CN 的规则去掉,让所有流量都走 proxy 再测一次试试。

    跟分流没多大关系…… 改成全局还是会漏

    我关掉 Chrome 的代理插件,用 ProxyCap 拦截 Chrome 流量,导入到 XRay 的 Socks5 Inbound。
    测试了一下,没发现泄露。
    可能 Tun 在 Win 下天生就水土不服吧。(当然了,这是 Microslop 的问题)

    你换 ProxyCap 吧。

  11. Meo597 commented on Jul 9, 2026

    @Meo597
    Collaborator

    缓解无效 @Meo597

    可能跟 TUN 无关是你自己没配置好导致的,那个 REG 生效了意味着查询不会多发一份走 TUN 网卡出去
    错误的配置该漏还是会漏

  12. Fangliding commented on Jul 9, 2026

    @Fangliding
    Member

    log里xray本身的dns系统没有往外发任何直连请求 肯定是系统还是什么地方的请求从TUN漏出去的

  13. Meo597 commented on Jul 9, 2026

    @Meo597
    Collaborator

    关了多宿主解析配好 xray 理论上防的住
    是不是 https 查询漏的,他 dns 出站没改写到国外

    总之先让 xray 不分流再看看吧

  14. LjhAUMEM commented on Jul 9, 2026

    @LjhAUMEM
    Collaborator

    使用 Windows TUN 时有管理员权限,要不自动把“智能多宿主解析”给关了吧

    不建议这么操作,修改注册表可能被识别为病毒,而且如果本地有 ipv6 似乎也不会遵循这个设置

  15. 101 remaining items

  16. reopened this on Sep 8, 2026
  17. added
    PR welcomeUnplanned idea, but welcome anyone to open PR for implementation
    on Sep 8, 2026
  18. lelegaga commented on Sep 11, 2026

    @lelegaga

    把网卡DNS改成虚拟网卡的ip试试吧

  19. RPRX commented on Sep 27, 2026

    @RPRX
    Member

    #6773 Linux 已解决问题,加了个新配置项 autoSystemDNS,我感觉改到 gateway 这方法也适用于 FreeBSD,@drTr0jan @brookwko 你们试试

    这个 issue 上面的讨论已确认 Windows 上改所有网卡的 DNS 也可行,等个有缘人 PR,或许只有 macOS 不行

  20. patterniha commented on Sep 28, 2026

    @patterniha
    Collaborator

    #6773 Linux 已解决问题,加了个新配置项 autoSystemDNS,我感觉改到 gateway 这方法也适用于 FreeBSD,@drTr0jan @brookwko 你们试试

    这个 issue 上面的讨论已确认 Windows 上改所有网卡的 DNS 也可行,等个有缘人 PR,或许只有 macOS 不行

    Changing the DNS settings of the network interfaces isn't a good idea. If the process is killed unexpectedly, or Windows shuts down abruptly, the modified settings are never restored, and the user is left with a broken DNS configuration on the next boot.

    in #6853, first, I implemented an IP-based idea. After several hours of discussion with Opus 5.5 (max), we decided to implement something close to the sing-box method. I conducted numerous tests and raised various questions, examining the approach from different angles, and we even resolved many of the flaws in the sing-box method.

  21. RPRX commented on Sep 30, 2026

    @RPRX
    Member

    #6853 Windows 上也已解决问题,加了个新配置项 autoSystemWfpBlockLeak,@patterniha 实测过,准备先发个 pre,你们也测测

    顺便把 Linux 上的改名为 autoSystemDnsToGateway,并改了些行为,但据称 Linux 上这个不够可靠 #6853 (comment) ,需要更多人的实测

    这个 issue 先标记关闭,还剩俩系统 macOS 和 FreeBSD,这俩 BSD 系统用的人就更少了,不过前者和 Linux 桌面比也不一定,等有缘人 PR 吧

    当然,macOS 上 $288 会和 iOS 上一样走 NE 框架,理论上会少很多这类系统层面的泄露问题,若苹果自身有些流量就是不进去那可能也没招

  22. 55575455 commented on Oct 2, 2026

    @55575455

    测试了最新版本,在 Windows 11 的 Hyper-V 虚拟机环境(Default Switch 默认交换机)下,仍然存在较严重的 DNS 泄漏问题:

    1. 现象:虽然公网出口 IP 显示为代理节点,但 DNS 泄漏测试仍然返回了大量宿主机本地运营商(中国移动)的 IPv4 与 IPv6 解析服务器。
    2. 环境:
      • 宿主机:Windows 11
      • 虚拟机:Hyper-V(默认 NAT 网络)
      • Xray 版本:v26.9.30
  23. 55575455 commented on Oct 2, 2026

    @55575455
    Image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    PR welcomeUnplanned idea, but welcome anyone to open PR for implementation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions