For the past few weeks, several macOS devices have experienced very slow internet access, random packet loss, and dropped connections when Tailscale is running with MagicDNS enabled alongside ThreatLocker Web Control. The affected users are in different countries and use different ISPs, so this does not appear to be limited to one local network. Tailscale and ThreatLocker support have both been contacted, but neither has identified the cause. The issue disappears when any one of the three components—Tailscale, MagicDNS, or ThreatLocker Web Control—is disabled. Different MagicDNS fallback resolvers, including NextDNS and Cloudflare, have also been tested without improvement. Has anyone encountered this combination on macOS, or have suggestions for isolating whether the problem is related to DNS interception, routing, or filtering conflicts?
1 Answer
Since changing the fallback resolver does not help and the devices are spread across unrelated networks, this sounds more like an interaction between the macOS network stack, Tailscale's DNS or route handling, and ThreatLocker's filtering layer than a bad upstream DNS provider. I would compare packet captures and route tables with each component enabled separately, then check whether ThreatLocker is inspecting or blocking traffic to Tailscale's DNS and tunnel addresses. It may also be worth testing whether disabling only MagicDNS while leaving Tailscale connected avoids the issue, since that would separate the tunnel from the DNS configuration.

We tested NextDNS, Cloudflare, and several other fallback resolvers, but none changed the behavior. The same symptoms appear on users with different ISPs and in different countries, and removing any one of Tailscale, MagicDNS, or ThreatLocker Web Control makes the systems behave normally. That makes a local resolver or ISP problem seem unlikely and points more toward a macOS compatibility or routing conflict between the two products.