I second boneyard suggestion to troubleshoot with tcpdump what is going on the wire. I just wanted to add that when you add example.com to the DNS Address Space list you are telling your client to make DNS resolution request for that domain through the tunnel using your internal DNS, so you need to make sure your DNS traffic is allowed to reach your DNS servers. If this is not what you want, you can leave this list empty and rely on public DNS resolution.
Also, if you use DNS Address Sapce, make sure when you generate the client package that "DNS Relay Proxy Service" is enabled