@jerry it's not pi-hole. The safezone.mcafee.com cert has a SSL_ERROR_BAD_CERT_DOMAIN error whether going via pi-hole or not. I can load infosec.exchange when connected to some VPN servers (some have an NGINX server error). When I connect successfully, a LetsEncrypt cert is used instead of the McAfee Safezone.