I want to share something that genuinely made me nervous, because I rely on VPNs for privacy — not unexplained network behavior.
Before wiping my desktop, I noticed some very strange DNS queries. After doing a full wipe and reinstall of Windows 11 (deleted all partitions, clean install, only Firefox afterwards), I reinstalled NordVPN — and the same strange DNS activity immediately returned.
NordVPN normally uses nordcdn.com for downloads and updates. I’ve seen the legitimate domain:
downloads77-windows.nordcdn.com
But when I tried logging into the NordVPN app after reinstall, both Wireshark and my pihole logs started showing malware‑like domains that look algorithmically generated:
icpsuawn1zy5amys.com
x9fnzrtl4x8pynsf.com
zwyr157wwiu6eior.com
p99nxpivfscyverz.me
njtzzrvg0lwj3bsn.info
These domains do not match anything in NordVPN’s official infrastructure. They don’t resemble normal CDN nodes, update servers, or telemetry endpoints. They look more like domains used in obfuscation, tunneling, or background beacons.
I used AI tools to investigate these domains, and none of them appear to be associated with NordVPN, Microsoft, Firefox, or any legitimate service. They’re random, suspicious, and have no clear purpose.
What worries me:
- These DNS queries appear only when NordVPN is installed
- They reappear even after a full OS reinstall, which rules out local malware
- They show up exactly when I try to log in to the NordVPN app
- They use random TLDs like .me and .info
- There is zero documentation explaining why a privacy‑focused VPN client would contact domains like these
I’m not accusing NordVPN of wrongdoing, but from a privacy perspective, unexplained DNS traffic from a VPN client is not acceptable. A VPN should reduce the attack surface — not introduce mysterious outbound queries that make users nervous.
So I’m asking the community:
- Has anyone else seen NordVPN generate these kinds of DNS records?
- Does NordVPN use obfuscated or algorithmically generated domains for updates or background services?
- Could this be related to meshnet, analytics, or something undocumented?
- Or is this a sign of something else entirely?
I’d appreciate insights from anyone running DNS‑monitoring tools like Pi‑hole, NextDNS, or Wireshark.
If a privacy tool behaves in a way that raises anxiety, that’s something worth discussing.
Source: r/vpnreviews · by /u/MuuarK