Blog
3 min read

DNS_PROBE_FINISHED_NXDOMAIN: What It Means and How to Fix It

NXDOMAIN means DNS says the domain name doesn't exist. Fixes for visitors (typos, DNS cache, changing DNS servers) and for site owners (missing records, nameserver changes, expired domains, propagation), with the commands to check what DNS is really saying.

This site can't be reached
Check if there is a typo in example.com.
DNS_PROBE_FINISHED_NXDOMAIN

NXDOMAIN means "non-existent domain". Your browser asked DNS for the address of that name, and DNS answered: there's no such domain (or no such subdomain). (What is a DNS server?)

The fix depends on whether it's your site or someone else's.

If you're visiting a site

1. Check for a typo

Genuinely the most common cause. exmaple.com, a missing www, .co instead of .com.

2. Try another network or device

If it works on your phone's mobile data but not your Wi-Fi, the problem is your network's DNS.

3. Clear your DNS cache

Your computer may have cached an old "doesn't exist" answer.

# Windows
ipconfig /flushdns

# macOS
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder

In Chrome, you can also visit chrome://net-internals/#dns and click Clear host cache.

4. Change your DNS server

Your internet provider's DNS may be failing. Switch to a public resolver like Cloudflare (1.1.1.1) or Google (8.8.8.8) in your network settings.

5. VPNs and blockers

VPNs, ad blockers, parental controls and corporate networks can block domains and return NXDOMAIN. Try turning them off.

If it's your site

1. Is there a DNS record for this exact name?

example.com and www.example.com are separate names. If you only created a record for one, the other returns NXDOMAIN. Same for subdomains like app.example.com. (DNS records explained)

Check what DNS says:

dig example.com
dig www.example.com
nslookup app.example.com

status: NXDOMAIN confirms the record is missing.

2. Did you just change nameservers?

When you move DNS to Cloudflare or another provider, you change the domain's nameservers at your registrar. Until that change spreads, some resolvers ask the old nameservers — which may no longer have your records. (DNS propagation explained)

Check which nameservers are in charge:

dig NS example.com

And make sure your records exist at those nameservers, not the old ones.

3. Did the domain expire?

An expired domain stops resolving. Check your registrar, and turn on auto-renew. A WHOIS lookup shows the expiry date. (What is a domain name?)

4. Is the domain suspended or not fully registered?

New registrations sometimes need you to verify your email address within a set number of days, or the domain is suspended. Check your inbox for a message from the registrar.

5. DNSSEC problems

If DNSSEC is enabled at the registrar but the DS record doesn't match your current DNS provider (common after moving providers), resolvers that validate DNSSEC treat the domain as broken. Disable DNSSEC at the registrar, move providers, then re-enable it with the new provider's record.

On localhost or a custom local name

If you see NXDOMAIN for a name like myapp.local or myapp.test, it's not in public DNS. Add it to your hosts file, or use localhost. (What is localhost?)

Quick checklist for site owners

  1. dig the exact name — NXDOMAIN?
  2. Record exists for that exact hostname?
  3. dig NS — records are at the nameservers actually in charge?
  4. Domain renewed and verified?
  5. DNSSEC consistent?

EasySpawn shows you exactly which DNS records to add for your domain and checks them for you, then sets up HTTPS as soon as they resolve. See how it works or join the waitlist.

Related: What Is a DNS Server? · DNS Records Explained · DNS Propagation Explained · How to Connect a Custom Domain

Keep reading