On Fire TV devices running Amazon Vega OS, a small number of DNS queries are sent outside the VPN tunnel. This happens at the operating system level and affects VPN apps on the platform generally—it is not specific to ExpressVPN.

The ExpressVPN team has identified and flagged three of such behaviors to the Amazon team. Amazon has identified the cause of one of these behaviors and plans to address it in an upcoming firmware update. The other two are intentional parts of how the operating system works.

Your encrypted traffic is not affected. Only DNS queries—the lookups that translate a domain name into an IP address—are involved.

Which queries are affected

1. Amazon network diagnostics (*.diagnostic.networking.aws.dev)

Vega OS performs a system-level check to confirm the device has working internet access. This runs over the physical network connection and cannot be routed through a VPN. This is intentional platform behavior.

2. Captive portal detection

Vega OS checks whether the network you are connected to requires sign-in through a browser page—the kind used by hotel, airport, and public Wi-Fi networks. This check runs over the Wi-Fi connection directly, because it needs to test the network itself rather than the VPN. This is also intentional platform behavior.

3. Selected app startup queries

When certain apps start, some DNS queries may bypass the VPN tunnel on Vega OS. We observed this behavior with Netflix startup domains, including appboot.netflix.com and secure.netflix.com. Amazon has confirmed this is unintended and is working on a fix.

What this means for your privacy

Only the DNS lookup is affected, not the traffic itself. Everything you actually do on the device—streaming, browsing, app activity—continues to travel through the encrypted VPN tunnel with your IP address hidden.

The practical effect is that your network operator or internet service provider may be able to see that a device on your network looked up these specific domains.

  • For items 1 and 2, this reveals nothing about your activity. These are generic system checks that every Vega OS device performs.
  • For item 3, it may indicate that the Netflix app was opened on the device. It does not reveal your Netflix account credentials, what you watched, how long you watched, or any other activity.

We have flagged these to Amazon, and Amazon has verified that items 1 and 2 are intentional operating system behavior and are not expected to change.

Amazon plans to deliver an improvement for item 3 in a Vega OS firmware update expected in late 2026. Firmware updates roll out over time, so your device may receive it later than that.

We will update this page once the update is available and we have confirmed the fix on our side.

If you have questions about this or anything else, contact the ExpressVPN Support Team.

Was this article helpful?

We're sorry to hear that. Let us know how we can improve.

A member of our Support Team will follow up on your issue.