For the past few weeks, several macOS devices have experienced serious connectivity problems when Tailscale is running with MagicDNS enabled alongside ThreatLocker Web Control. Internet access becomes very slow, connections randomly drop, and packets appear to be lost. The affected users are in different countries and use different ISPs, so this does not appear to be limited to one local network. Changing the fallback DNS resolver—including NextDNS and Cloudflare—or removing any one of Tailscale, MagicDNS, or ThreatLocker Web Control makes the problem disappear. Support from both vendors has not yet identified the cause. Has anyone run into this combination before, and what diagnostic steps or configuration changes helped?
1 Answer
The fallback resolver is worth checking, but since you have tested several providers and the issue follows the combination across different networks, this sounds more like an interaction between the macOS network extension layers than a bad DNS service. Both MagicDNS and web filtering may be installing DNS or packet-handling components, and their order or behavior can change after an update. I would compare a failing Mac and a working Mac while collecting packet captures, DNS logs, route tables, and the status of both network extensions. Also test with only DNS filtering enabled in ThreatLocker, then only web filtering, to identify which component creates the conflict.

That matches what we are seeing: swapping resolvers does not change anything, and the affected machines are on unrelated networks. Disabling either MagicDNS or Web Control restores normal performance, so we are focusing on the macOS extension interaction rather than the upstream DNS provider.