the VPN had an IP address so it didn't need that, and then the devices were going through the VPN to get DNS. this is normal with stuff like wireguard, usually you set one or two DNS IP addresses to use with it and they get elevated to higher priority (lower metric) than the rest of the connections ...