Common causes
- No A, AAAA or CNAME record exists for the exact hostname, often the www or a new subdomain
- The domain's nameservers at the registrar point to a DNS provider that has no zone for it
- The domain has expired, been suspended or put on clientHold by the registrar
- A recent nameserver change has not finished propagating, or a cached NXDOMAIN is still stored
- A typo in the domain, or in a local hosts file entry
- The visitor's DNS resolver, VPN or security software is failing or blocking the name
How to fix it
- Check public DNS. Run dig example.com +short and dig www.example.com +short, or nslookup example.com 1.1.1.1. If public resolvers also return NXDOMAIN, the problem is in your DNS setup, not the visitor.
- Check the domain status. Run whois example.com and look at the expiry date and status. clientHold or serverHold means the registrar has taken the domain out of DNS; renew it or verify the registrant email.
- Verify nameservers. Compare the nameservers listed at the registrar with those of your DNS host (cPanel, Cloudflare, Hostinger). Run dig NS example.com to see what the internet sees.
- Add the missing records. In the DNS zone, add an A record for @ pointing to your server's IP and a CNAME (or A) for www. Do the same for any subdomain that fails.
- Wait out caching, then flush. After changes, cached NXDOMAIN answers can last up to the zone's negative-cache TTL. Flush local caches: ipconfig /flushdns on Windows, sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder on macOS, and chrome://net-internals/#dns in Chrome.
- Rule out the local machine. Check the hosts file for stale entries and try another network or a public resolver such as 1.1.1.1 or 8.8.8.8.
Shell (diagnose DNS)
dig example.com +short
dig www.example.com +short
dig NS example.com +short
nslookup example.com 1.1.1.1
whois example.com | grep -i -E 'expir|status|name server' How to stop it happening again
- Enable auto-renew on domains and keep the registrant email current
- Create www and subdomain records when you create the site, not after launch
- Lower TTLs a day before planned DNS or nameserver changes