yes, the DNS resolves correctly and the port is open, checked with online port checker. Installing on a freshly erased Apple Silicon machine, I got the following-
[netclient] 2022-05-19 20:09:38 joining test at api.wg.domain.com.au:443
[netclient] 2022-05-19 20:09:38 starting wireguard
[netclient] 2022-05-19 20:09:45 certificates/key saved
[netclient] 2022-05-19 20:10:15 unable to connect to broker, retrying ...
[netclient] 2022-05-19 20:10:15 could not connect to broker broker.wg.domain.com.au connect timeout
[netclient] 2022-05-19 20:10:15 connection issue detected.. attempt connection with new certs
[netclient] 2022-05-19 20:10:15 certificates/key saved
[netclient] 2022-05-19 20:10:46 could not connect to broker at broker.wg.domain.com.au:8883
[netclient] 2022-05-19 20:10:46 sent a node update to server for node Servicemax-2local , axxxce5-30a1-40ax0-877a-xxx
So the client does connect and register (MUCH slower than it used to be, in case that's important), and on this machine there is no weird aliasing happening to /etc/netclient, so that bit seems to be a non-issue. But something funny about the mq broker connection.
I've sent a copy of the logs for the 'join' command via email.
Let me know if you have any ideas...