lemoncert
AccountGet certificate

Sideloaded app won't install on VPN or ad-block DNS? Here's why (and the fix)

VPNs, router VPNs, AdGuard, NextDNS and Pi-hole block the Apple endpoints iOS uses to verify certificates, breaking OTA installs. Learn what to whitelist and how to work around it.

TroubleshootingUpdated Sep 17, 2026·3 min read

When you install a signed app over-the-air, iOS fetches an install manifest, downloads the IPA, then validates the certificate with Apple. Any filter in the path — VPN, DNS ad-blocker, corporate proxy — can silently break one of those steps, and iOS just reports *Unable to Install*.

Common culprits

  • VPN apps on the phone (NordVPN, Proton, Cloudflare WARP, etc.).
  • Router-level VPN (ASUS, GL.iNet, pfSense…) — invisible on the phone but affects the whole Wi-Fi network.
  • Ad-block DNS — AdGuard DNS, NextDNS, Pi-hole, ControlD. Their blocklists often include Apple telemetry/OCSP hosts.
  • iCloud Private Relay in rare cases.

The 30-second fix

  1. Turn Wi-Fi off and install on 4G/5G. This bypasses router VPNs and DNS filters at once.
  2. Turn off any VPN app for the duration of the install.
  3. Retry the install from your signer app or from lemoncert.

Whitelisting instead

If you must keep the DNS filter, allow these Apple hosts: ocsp.apple.com, ocsp2.apple.com, ppq.apple.com, iosapps.itunes.apple.com, gs.apple.com, humb.apple.com, plus the site you install from (lemoncert.com).

Once an app is installed and trusted, it keeps working on VPN. The restriction only matters during installation and the first launch.
Need a certificate?
Generated the instant your crypto payment confirms. Feather & KSign one-tap install included.
Get my certificate

Keep reading