Set myservice.example.com to an internal address like 10.10.100.x. Those addresses are not routable on the public internet. They can only be reached from a local network which the VPN tunnels you into.
If your VPN also supplies DNS to clients, can also add a private zone if its supported so nobody can resolve that internal address except those clients.