Ffile2fix
Sign in Get started

How to fix DNS_PROBE_FINISHED_NXDOMAIN for your domain

This site can't be reached. Check if there is a typo in example.com. DNS_PROBE_FINISHED_NXDOMAIN

NXDOMAIN is the DNS answer for "this name does not exist": the browser could not find any IP address for the domain or subdomain. The web server is never contacted, so the fix is in DNS, the registrar or the visitor's resolver.

Also appears as: DNS_PROBE_FINISHED_NXDOMAIN · Hmm. We're having trouble finding that site. We can't connect to the server at example.com. (Firefox) · example.com's server IP address could not be found. · curl: (6) Could not resolve host: example.com

Common causes

  • No A, AAAA or CNAME record exists for the exact hostname, often the www or a new subdomain
  • The domain's nameservers at the registrar point to a DNS provider that has no zone for it
  • The domain has expired, been suspended or put on clientHold by the registrar
  • A recent nameserver change has not finished propagating, or a cached NXDOMAIN is still stored
  • A typo in the domain, or in a local hosts file entry
  • The visitor's DNS resolver, VPN or security software is failing or blocking the name

How to fix it

  1. Check public DNS. Run dig example.com +short and dig www.example.com +short, or nslookup example.com 1.1.1.1. If public resolvers also return NXDOMAIN, the problem is in your DNS setup, not the visitor.
  2. Check the domain status. Run whois example.com and look at the expiry date and status. clientHold or serverHold means the registrar has taken the domain out of DNS; renew it or verify the registrant email.
  3. Verify nameservers. Compare the nameservers listed at the registrar with those of your DNS host (cPanel, Cloudflare, Hostinger). Run dig NS example.com to see what the internet sees.
  4. Add the missing records. In the DNS zone, add an A record for @ pointing to your server's IP and a CNAME (or A) for www. Do the same for any subdomain that fails.
  5. Wait out caching, then flush. After changes, cached NXDOMAIN answers can last up to the zone's negative-cache TTL. Flush local caches: ipconfig /flushdns on Windows, sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder on macOS, and chrome://net-internals/#dns in Chrome.
  6. Rule out the local machine. Check the hosts file for stale entries and try another network or a public resolver such as 1.1.1.1 or 8.8.8.8.

Shell (diagnose DNS)

dig example.com +short
dig www.example.com +short
dig NS example.com +short
nslookup example.com 1.1.1.1
whois example.com | grep -i -E 'expir|status|name server'

How to stop it happening again

  • Enable auto-renew on domains and keep the registrant email current
  • Create www and subdomain records when you create the site, not after launch
  • Lower TTLs a day before planned DNS or nameserver changes

Frequently asked questions

How long does DNS propagation take?

New records on existing nameservers usually work within minutes. Nameserver changes can take up to 24-48 hours, and a cached NXDOMAIN may persist for the negative-cache TTL set in the zone's SOA record.

Why does the domain work but www does not?

The bare domain and www are separate DNS names. If the zone has no record for www, it returns NXDOMAIN; add a CNAME for www pointing to the bare domain.

Is DNS_PROBE_FINISHED_NXDOMAIN a server error?

No. The browser never reaches your server; the name lookup fails first. Restarting the web server will not help.