redirecting DNS traffic needs to happen before the NON_TOR exception. Otherwise DNS package could leak to the local router. [(diff)][1] [1]: https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy?action=diff&version=56 URL: https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy?version=56