But what about HSTS and HSTS preloading? This sounds more like a deauth/captive portal phish to me.
this is a more detailed, and first order account of things from reliaquest itself.
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-t...
apparently a full funnel VPN policy prevents the workflow.