Sideloaded app won't install on VPN or ad-block DNS? Here's why (and the fix)
VPNs, router VPNs, AdGuard, NextDNS and Pi-hole block the Apple endpoints iOS uses to verify certificates, breaking OTA installs. Learn what to whitelist and how to work around it.
When you install a signed app over-the-air, iOS fetches an install manifest, downloads the IPA, then validates the certificate with Apple. Any filter in the path — VPN, DNS ad-blocker, corporate proxy — can silently break one of those steps, and iOS just reports *Unable to Install*.
Common culprits
- VPN apps on the phone (NordVPN, Proton, Cloudflare WARP, etc.).
- Router-level VPN (ASUS, GL.iNet, pfSense…) — invisible on the phone but affects the whole Wi-Fi network.
- Ad-block DNS — AdGuard DNS, NextDNS, Pi-hole, ControlD. Their blocklists often include Apple telemetry/OCSP hosts.
- iCloud Private Relay in rare cases.
The 30-second fix
- Turn Wi-Fi off and install on 4G/5G. This bypasses router VPNs and DNS filters at once.
- Turn off any VPN app for the duration of the install.
- Retry the install from your signer app or from lemoncert.
Whitelisting instead
If you must keep the DNS filter, allow these Apple hosts: ocsp.apple.com, ocsp2.apple.com, ppq.apple.com, iosapps.itunes.apple.com, gs.apple.com, humb.apple.com, plus the site you install from (lemoncert.com).