The test was run on one Mac on 5 October 2026, connected to Mullvad's bg-sof-wg-001 server in Sofia. Every command on screen really ran. My IP address and location were masked as the output was printed.
With the VPN off I opened three sites. Each site name crossed the wire in the clear inside the Mac's DNS request. With Mullvad on, the same port 53 listener caught no packet. Everything leaving the wire was encrypted UDP to the Sofia server.
With lockdown mode on I cut the tunnel myself. The outage lasted 12 seconds. During that time 0 packets left the Wi-Fi card and curl could not even resolve the site name.
For DAITA I connected to the same server twice and recorded 60 seconds each time, opening the same three sites in the same order. With DAITA off there were 2955 packets in 76 different sizes. With it on there were 13316 packets in only 2 sizes. Even with no site loading, 155 packets per second flowed, compared with 60 with DAITA off.
For the obfuscation modes I had tshark, the command line version of Wireshark, read each capture. Without obfuscation all 3598 packets were recognised as WireGuard. With UDP2TCP, Shadowsocks, QUIC and LWO the count of recognised packets was 0. In WireGuard port mode only the port changed, and all 245 packets were recognised again.
With multihop on, the wire showed only the Sofia server, while am.i.mullvad.net reported the exit in Stockholm. With DNS blocking on, doubleclick.net, google-analytics.com and instagram.com got no address, while debian.org did.
For split tunnelling, macOS Full Disk Access was granted but Mullvad did not see the permission. Mullvad cut the whole connection. Neither the excluded curl nor Python got an answer, and nothing leaked.
At evidence moments the video is slowed down and held on that frame. Long parts such as the 60 second measurements are sped up. Three short path drawings only show where the traffic goes and carry no results.
The measurements were taken on one machine, on one network, in one session. That the extra packets with DAITA on are cover packets cannot be proven directly, because the encrypted content cannot be read; it follows from the difference between the two captures.
Measured values
Raw values can be read from the logs in the downloadable data package.
- DNS, VPN on
- 0 packets on port 53
- Lockdown, tunnel down
- 0 outgoing packets, outage 12.0 s
- DAITA off
- 2955 packets, 76 sizes, 1.5 MB
- DAITA on
- 13316 packets, 2 sizes, 18.8 MB
- No obfuscation
- 3598 of 3598 packets WireGuard
- UDP2TCP, Shadowsocks, QUIC, LWO
- 0 packets recognised as WireGuard
- Multihop connect median
- 101 ms and 126 ms
- Quantum-resistant key exchange
- connect 0.30 s and 0.94 s
