yup that is correct.

thanks for verifying!, I was not sure about this.

--

well I don't think hijacking is the solution for this even if I would use a hardcoded ipset, I need to figure something else I could split route on the wireguard client side that might be a better idea, atleast I know now dnsmasq ipsets are only for upstream domains now :slight_smile: