A user bug report on the mesh VPN tool's optional Mullvad exit node (a traffic routing add on) resurfaced on Hacker News, and readers can self test the leak at browserleaks.com/dns while waiting for vendor comment.
A user-submitted bug report on Tailscale's public issue tracker, filed roughly three years ago against version 1.48.2, says the mesh-VPN tool's optional Mullvad exit-node upgrade leaks DNS queries on macOS, Windows, and iOS. The thread resurfaced on Hacker News this week (item 49107441), putting a recurring integration bug in front of a fresh audience.
The reproduction is short: subscribe to Mullvad through Tailscale, connect to an exit node, then check browserleaks.com/dns. The original report (Tailscale issue 9284) says requests meant to stay inside the tunnel reach the host's normal resolver, often the ISP, exposing the browsing history the stack is meant to hide.
Two related trackers show this is a class of bug rather than a one-off. Issue 16731 is a separate "DNS leak in Mullvad add-on" report, and issue 10711 is a still-open feature request for user-facing DNS control on Mullvad exit nodes. Tailscale's KB 1258 on Mullvad exit nodes documents how the integration is meant to work but does not address the leak claim.
No Tailscale engineer reply is captured in the available sources, and Mullvad has not been quoted. Until a vendor comment or a current-version retest lands, this is a testable claim rather than a confirmed finding. Affected users can run the browserleaks check, follow issue 9284 for vendor acknowledgment, and read newer Tailscale release notes before drawing a final line.