Skip to content
DnsLister Forum

Where domain hunters compare notes

NordVPN client causing unexplained DNS queries even after a full Windows reinstall — make me nervous

I want to share something that genuinely made me nervous, because I rely on VPNs for privacy — not unexplained network behavior.

Before wiping my desktop, I noticed some very strange DNS queries. After doing a full wipe and reinstall of Windows 11 (deleted all partitions, clean install, only Firefox afterwards), I reinstalled NordVPN — and the same strange DNS activity immediately returned.

NordVPN normally uses nordcdn.com for downloads and updates. I’ve seen the legitimate domain:

downloads77-windows.nordcdn.com

But when I tried logging into the NordVPN app after reinstall, both Wireshark and my pihole logs started showing malware‑like domains that look algorithmically generated:

icpsuawn1zy5amys.com
x9fnzrtl4x8pynsf.com
zwyr157wwiu6eior.com
p99nxpivfscyverz.me
njtzzrvg0lwj3bsn.info

These domains do not match anything in NordVPN’s official infrastructure. They don’t resemble normal CDN nodes, update servers, or telemetry endpoints. They look more like domains used in obfuscation, tunneling, or background beacons.

I used AI tools to investigate these domains, and none of them appear to be associated with NordVPN, Microsoft, Firefox, or any legitimate service. They’re random, suspicious, and have no clear purpose.

What worries me:

  • These DNS queries appear only when NordVPN is installed
  • They reappear even after a full OS reinstall, which rules out local malware
  • They show up exactly when I try to log in to the NordVPN app
  • They use random TLDs like .me and .info
  • There is zero documentation explaining why a privacy‑focused VPN client would contact domains like these

I’m not accusing NordVPN of wrongdoing, but from a privacy perspective, unexplained DNS traffic from a VPN client is not acceptable. A VPN should reduce the attack surface — not introduce mysterious outbound queries that make users nervous.

So I’m asking the community:

  • Has anyone else seen NordVPN generate these kinds of DNS records?
  • Does NordVPN use obfuscated or algorithmically generated domains for updates or background services?
  • Could this be related to meshnet, analytics, or something undocumented?
  • Or is this a sign of something else entirely?

I’d appreciate insights from anyone running DNS‑monitoring tools like Pi‑hole, NextDNS, or Wireshark.
If a privacy tool behaves in a way that raises anxiety, that’s something worth discussing.

Source: r/vpnreviews · by /u/MuuarK

Leave a Reply

Your email address will not be published. Required fields are marked *