Web

NXDOMAIN Error (DNS_PROBE_FINISHED_NXDOMAIN): How to Fix It

Talha Aslan 19 min read 3 views

What is the DNS_PROBE_FINISHED_NXDOMAIN error?

The DNS_PROBE_FINISHED_NXDOMAIN error is a Chrome and Chromium browser message that means your browser could not find an IP address for the domain you typed. The DNS server answered NXDOMAIN, which means "this domain does not exist." The browser never reaches the web server, because it does not know where to go.

NXDOMAIN is the common name for the DNS response code "Name Error." RFC 8499 defines it as a response saying that the queried name does not exist. In other words, the problem usually sits in the domain's DNS records or in your own DNS resolver, not in the website itself.

In this guide we first separate who owns the problem. Then we cover the steps a visitor can take, followed by what a site owner should check: name servers, records, and domain expiry. You can also test any domain with our DNS lookup tool.

Who should fix an NXDOMAIN error: the visitor, the site owner, or the server admin?

Finding the right owner saves time, because each role holds a different set of controls. If you can open the same site on another phone or on mobile data, the problem is probably your device or network. If nobody can open it, the problem belongs to the site owner.

RoleWhat they controlWhere to look first
Site visitorOwn device and networkDNS cache, DNS server, hosts file, VPN
Site ownerDomain registrar accountDomain expiry, name servers, typos
Server adminDNS zone and serverA, AAAA and CNAME records, TTL value
Hosting providerHosting and often the DNS panelAccount status, a closed DNS zone

One question settles most cases: does the error appear for everyone, or only for you? If everyone sees it, the domain or the DNS zone has a problem. If only you see it, a setting on your device or network still holds old information.

On a small business site, the owner and the admin are often the same person. Even so, we recommend keeping the order. First rule out your own side, then look at the domain itself.

How does the DNS_PROBE_FINISHED_NXDOMAIN error happen in DNS?

Before the browser opens a page, it asks the operating system for the IP address of the domain. The system passes the question to the configured resolver, which is usually your internet provider's server or your router. The resolver then walks the DNS tree from the root servers down to the domain's authoritative server.

If the authoritative server says "I have no such name," the resolver returns NXDOMAIN. You get this answer when the domain is not registered, when it expired and was deleted, or when its name servers point to an empty place. RFC 2308 describes this behavior and how resolvers cache negative answers.

According to that document, a "does not exist" answer can also be stored for a while. This detail explains why some visitors keep seeing the error after the owner fixes the record. So a delay between the fix and the result is normal.

What is the difference between NXDOMAIN and other DNS or connection errors?

Not every "site can't be reached" message points to the same problem. For example, NXDOMAIN is the case where DNS clearly says "this name does not exist." When the resolver cannot answer at all, you usually see a different code such as SERVFAIL and a different error screen.

  • DNS_PROBE_FINISHED_NXDOMAIN: DNS answered that the name does not exist.
  • DNS_PROBE_FINISHED_NO_INTERNET: The device has no connection, or it cannot reach DNS at all.
  • SERVFAIL: The resolver could not finish the query, which points to a server or configuration problem.
  • HTTP 404 and similar codes: The name resolved, the server replied, and the page was not found.

This distinction matters, because it tells you where to look. If the name resolves, DNS is healthy, and you should look at the server or the application instead. Knowing that the error appears at the DNS stage points you to the right layer.

What are the most common causes of the DNS_PROBE_FINISHED_NXDOMAIN error?

The causes fall into two groups. Real gaps on the domain side make up the first group. Stale or broken information in the visitor's own environment makes up the second. In the list below, we order them by how easy they are to check, not by how often they occur.

  • You typed the domain wrong, or you mixed up the extension.
  • The domain expired and its DNS service stopped.
  • You registered a new domain but have not set its name servers yet.
  • The name servers point to a server that holds no zone for the domain.
  • An A, AAAA or CNAME record is missing from the DNS zone.
  • During a move, your old hosting provider closed the DNS zone.
  • On your device, the DNS cache, hosts file, VPN or a filtering service gives wrong answers.

The first six items belong to the site owner. However, the last item usually explains why you see the error only on certain devices or networks.

In what order should you troubleshoot an NXDOMAIN error?

A fixed order beats random changes for two reasons. First, you finish the quick and harmless checks early. Second, each step narrows the cause, so you also see which role should step in.

  1. Check the address letter by letter, and try the version with and without www.
  2. Open the site on another device and on mobile data.
  3. Check the domain's expiry date and name servers if other devices fail too.
  4. Clear the DNS cache when only your device fails.
  5. Next, change the DNS server, then check the hosts file and the VPN.

This order puts the cheapest diagnosis first. For example, spending hours on DNS settings because of a mistyped address is a common but avoidable waste of time.

How do you clear the DNS cache as a visitor?

Your browser and your operating system store the IP addresses they find, so pages load faster. If the owner just fixed the domain, your device may still hold the old "does not exist" answer. So clearing the cache often removes the error right away.

On Windows, open Command Prompt as administrator and run this command:

ipconfig /flushdns

On macOS, people commonly run the two commands below in Terminal. The effect can vary by macOS version, so check Apple's support page if they do not work:

sudo dscacheutil -flushcache
sudo killall -HUP mDNSResponder

On Linux distributions that use systemd-resolved, this command empties the cache:

sudo resolvectl flush-caches

Chrome also keeps its own internal cache. Type chrome://net-internals/#dns in the address bar and click "Clear host cache." Then retry the site in an incognito window.

Does changing your DNS server fix an NXDOMAIN error?

Sometimes it does. A misconfigured or slow-updating internet provider resolver can return NXDOMAIN even for a domain that exists. Then, when you switch to a public resolver, the site often loads right away.

Google publishes 8.8.8.8 and 8.8.4.4 for IPv4, and 2001:4860:4860::8888 and 2001:4860:4860::8844 for IPv6. You can find the Windows and macOS steps in the Google Public DNS documentation. Also, you need administrator rights to change the setting.

Keep one point in mind: a new DNS server cannot fix a domain that is truly not registered. In practice, whichever resolver you pick, the answer for a deleted domain stays the same. If the error remains after the switch, the problem most likely belongs to the site owner.

In addition, you can toggle Chrome's "Use secure DNS" option under Privacy and security. It makes the browser send DNS queries through a path that is separate from the operating system. Sometimes it solves the error and sometimes it exposes one, so test both states.

What should you do if NXDOMAIN appears on your phone?

On a phone, the cause is often the gap between Wi-Fi and mobile data. If the site opens on mobile data but not on Wi-Fi, your router or home provider's DNS is the likely culprit. In the opposite case, instead, the mobile carrier's resolver may cause the trouble.

  • Toggle airplane mode on and off to refresh the connection.
  • Turn Wi-Fi off and test on mobile data, then do the reverse.
  • On Android, switch the Private DNS setting off and on, or set it to automatic.
  • Clear the browser cache and site data.
  • Restart your router.

Also check the in-app browser. If a social app's built-in browser shows the error, copy the link and open it in Chrome or Safari. That way you learn whether the app or the network causes the problem.

Terminal commands are rare on phones. So, changing the connection type is the fastest and safest diagnosis.

Can the hosts file cause an NXDOMAIN error?

Yes, although the opposite is more common: a line in the hosts file points the domain to an old or wrong address. The browser reads this file before it asks DNS. Also, developers sometimes add a line for testing and forget it, so the site fails on that one computer for years.

The file lives in these places:

  • Windows: C:\Windows\System32\drivers\etc\hosts
  • macOS and Linux: /etc/hosts

Open the file with administrator rights in a text editor and search for the problem domain. If you see a line like the one below, disable it by adding # at the start:

203.0.113.10 example.com www.example.com

The IP address in the example is for documentation only. Then clear the DNS cache after you save the change. If you never edited the hosts file and feel unsure, do not change it; just read it.

Can a VPN, antivirus or DNS filter cause an NXDOMAIN error?

Yes, they can. VPN clients often switch you to their own DNS server. That server may know the company's internal names but mishandle public domains. Turning the VPN off and retrying is a quick test.

Also, some security software and filtering DNS services return NXDOMAIN for domains they block. Parental controls, corporate content filters and ad-blocking DNS services are examples. In that case the error does not mean the site is broken. It means the filter is active.

Still, a router can create a similar effect. Restarting it can clear a bad DNS cache. Because it is a shared setup, if you sit on a corporate network, do not change the setting yourself; send the domain name and the time of the error to your IT team.

How do you check domain expiry if you own the site?

When a site fails on every device, the first place to look is the domain's validity. With our WHOIS lookup tool you can see the expiry date, the registration status and the name servers. Logging in to your registrar account and checking the renewal screen gives the same answer.

ICANN publishes a recovery policy for expired generic top-level domains. According to it, registrars must send two renewal reminders, roughly one month and one week before expiry. After expiry, DNS service for the domain may stop, which means your website and email stop working too. You can read the details on ICANN's page for domain owners.

One warning: these rules apply to generic extensions. Country-code domains have their own renewal and recovery rules, so check your registrar's documentation. Also keep your contact details current, so reminders do not go to an old address.

How do you verify an NXDOMAIN error when name servers are wrong?

Name server (NS) records tell the world which servers manage the domain's DNS zone. These records live in the top-level domain registry, and you change them at the registrar where you bought the domain. If they point to a server that holds no zone for your domain, resolvers get a "no such name" answer.

You can verify this with the dig command. The commands below work with your own domain in place of example.com:

dig example.com NS +short
dig example.com A +short
dig +trace example.com

The first command lists the name servers. Then the second shows the A record. Finally, the third follows the resolution chain from the root and shows at which step the "does not exist" answer appears.

Watch out for one trap. You may have created the zone at the new provider, but the NS records at your registrar still point to the old one. In that case nobody ever queries the new zone. The place that holds the zone and the place that the NS records name must match.

If dig is not available on Windows, nslookup does the job. For example, nslookup example.com 8.8.8.8 sends the query straight to Google's resolver and lets you compare results.

How do you read the status line in dig output?

First, the header of a dig reply contains a status value. It shows the DNS response code and is the shortest path to a diagnosis. For example, if you see status: NXDOMAIN, the problem sits firmly in the DNS layer.

status valueMeaningNext step
NOERRORThe name exists and the query workedCheck whether the answer section holds a record
NXDOMAINThe name does not existCheck domain expiry, name servers and the record name
SERVFAILThe resolver could not finish the queryTry another resolver and the authoritative server

If you see NOERROR but the answer section is empty, the name exists, yet the record type you asked for does not. For example, you ask for an A record, and the zone holds only an MX record. People often confuse this with NXDOMAIN and head in the wrong direction.

Keep in mind that different resolvers can give different answers. So send the same query to your own resolver and to a public one. If both give the same answer, the problem sits in the domain itself, not on your device.

How do you fix a missing A, AAAA or CNAME record?

Even with correct name servers, you still see NXDOMAIN when the zone has no record for that name. Often the root domain works while the www name stays undefined. A visitor who types www gets the error, because that name never existed in the zone.

Record typeWhat it doesWhat happens if it is missing
AMaps a name to an IPv4 addressThe name does not resolve; NXDOMAIN or an empty answer appears
AAAAMaps a name to an IPv6 addressOnly IPv6 visitors have trouble
CNAMEPoints a name to another nameAliases such as www do not work
NSLists the servers that manage the zoneThe whole domain does not resolve

To fix it, add a CNAME for www in the DNS panel, or create an A record that uses the same IP as the root name. If you are preparing for IPv6, read the AAAA part of our IPv6 guide. If your hosting provider gave you a specific value, enter that value in the panel.

How long does DNS propagation take, and why do you have to wait?

DNS changes do not reach the whole world at once, because resolvers keep answers for a period called the TTL. A long TTL means old information circulates longer. So "propagation" really means waiting for old caches to expire on their own.

Giving an exact number of hours would not be honest. The time depends on the record's TTL and on the resolver your visitor uses. For name server changes, the top-level registry records also play a role. That is why some visitors see your site while others do not for a while after a change.

Negative caching works in the same way. According to RFC 2308, a "does not exist" answer can be stored too, and its lifetime depends on values in the zone's SOA record. If you just added a record and still see NXDOMAIN, assume your resolver holds the old answer. Waiting and clearing the cache is often enough.

Here is an example calculation. If a record has a TTL of 3600 seconds, resolvers may keep the answer for up to one hour. If you lower the TTL to 300 seconds, old data circulates for a much shorter time. However, this change itself waits for the old TTL to run out, so apply it at least one old TTL before a migration.

How do you avoid NXDOMAIN when moving hosts or registering a new domain?

An NXDOMAIN during a move usually happens when the old DNS zone closes before the new one is ready. If you follow the order below, the risk drops:

  1. Lower the TTL of your records before the move.
  2. Create the DNS zone at the new provider and copy every record exactly, including MX and TXT.
  3. Verify the records by querying the new name servers with dig.
  4. Change the NS records in your registrar account.
  5. Wait long enough for caches to expire, then close the old zone.

For the SEO side, also review our website migration SEO checklist. A DNS outage means search engine bots cannot reach the site either.

If you register a new domain, set the NS and A records before you launch the site. An empty domain does not resolve either, and visitors see NXDOMAIN.

Can a wrong redirect cause an NXDOMAIN error?

Yes. Sometimes the visitor types the right address, but your site redirects them to a different domain that does not exist. The browser follows the redirect, gets NXDOMAIN for the new address, and shows the error page. If the address bar shows a different domain than the one you typed, consider this scenario.

Typical sources include a wrong site address in the CMS settings, an old test domain left in a redirect rule, and address values that nobody updated when the site moved from staging to live. In this case the server works, so the error looks like DNS, but the real cause is an application setting.

To inspect the redirect from the command line, look at the response headers:

curl -I https://example.com

The Location header in the output shows where the redirect goes. If the domain in that header is wrong, fix it in the CMS settings or in the server's redirect rules.

Do ads and campaign links carry an NXDOMAIN risk?

They do. If an ad's destination URL or a newsletter link contains a typo, the person who clicks lands on an NXDOMAIN screen. You also spend budget on those clicks, but nobody reaches your site. Opening every link on a real device before a campaign goes live is the cheapest insurance.

The risk grows when a domain expires. Your ads, email signatures, social profile links and Google Business Profile all break at once. Therefore, turning on auto-renewal and putting the expiry date in your calendar is a sensible precaution.

In addition, when you build UTM links, copy the domain instead of typing it. A single wrong letter can waste hundreds of clicks.

Before a campaign, also confirm that the target domain has a valid SSL certificate. Even when DNS resolves, a certificate error turns visitors away.

What should you do if only a subdomain shows NXDOMAIN?

Sometimes the main domain works, but a subdomain such as blog.example.com or shop.example.com returns NXDOMAIN. The cause is usually simple: the DNS zone has no record for that subdomain. Because your main site works, you do not need to suspect DNS as a whole.

First, verify the record name. For example, a panel may expect only "blog," but you typed the full name. In some panels that creates a record named example.com.example.com. Next, check the record type: if the subdomain uses a CNAME, the target name must resolve as well.

After you create the subdomain, the server also needs a virtual host for it. However, that is a separate job from DNS. If DNS resolves but the page does not load, the problem is no longer NXDOMAIN, and you should look at the server setup together with your hosting provider.

Do you need a new domain if you cannot recover the old one?

If the domain expired and the recovery period also ended, someone else may have registered it. In that case you have to rebuild your brand on a new domain. You cannot redirect from the old address, because its DNS no longer belongs to you.

When you pick a new domain, choose a name that is close to your brand, easy to remember and clear to spell. Our guide on how to choose a domain name for your business covers the details. Also expect that you may not regain all the links and search visibility the old address had.

Then update your email addresses, Google Business Profile, ad accounts and the links on your social profiles. That way customers stop going to the old address. For such a move, a migration plan that covers crawling and indexing is the healthiest path.

Does an NXDOMAIN error affect SEO and email?

Yes. Search engine bots also need DNS to reach a site. The Crawl Stats report in Google Search Console shows, under host status, when the DNS server did not recognize the hostname or did not respond. Google's documentation advises you to check with your registrar if you see errors.

A short outage usually does not cause big trouble, but a long DNS failure can hurt crawling and visibility. There is no exact threshold, so fix the problem as soon as you can.

Email depends on the same DNS zone. If MX records do not resolve, incoming mail never reaches you. If your domain does not resolve, check both the website and the mailbox, and watch for bounce messages from senders.

When should you leave an NXDOMAIN problem to your hosting provider?

DNS settings look simple, but one wrong change can take down the whole site and email. Do not go on alone in these cases:

  • You do not know what email records such as MX, SPF and DKIM do.
  • The domain uses DNSSEC and you must change the DS record.
  • You plan an irreversible action such as a domain transfer or a lock release.
  • You are on a corporate network and someone asks you to change the DNS server or the router.

We are a digital marketing and web team, not a hosting company. Therefore we based this guide on official documentation and standards. If your provider's panel shows a different screen, follow their instructions first.

Which step should you try first, and in what order?

In short, follow this order: check the address, test with another device, look at the domain's expiry and name servers, then verify the A and CNAME records in the zone. Move on to cache, DNS server, hosts file and VPN steps only if the problem affects just you.

Domain management, hosting and technical SEO connect with each other. To review your infrastructure choices, read our guide to choosing web hosting. For DNS resilience, our article on Anycast DNS adds more detail.

For business mail on your own domain, see our business email guide. If you want to review how technical infrastructure errors affect your visibility, our SEO consulting service covers that work.

Frequently Asked Questions

Does an NXDOMAIN error mean my website was hacked?
No. NXDOMAIN means DNS found no record for the domain. The usual causes are an expired domain, a missing name server or A record, or stale cache on a device. However, if you suspect that someone changed your DNS records without permission, review your registrar account's login history and reset your password.
Does the DNS_PROBE_FINISHED_NXDOMAIN message appear only in Chrome?
The exact wording belongs to Chrome and Chromium-based browsers. Other browsers describe the same situation in their own words, such as server not found. The underlying cause stays the same: DNS gave no answer for the domain. So testing in another browser helps little, while testing on another network helps a lot.
The domain is correct but only I cannot open the site. What should I do?
This points to your device or network. First clear the DNS cache, then check your hosts file for a line about that domain. Next turn off your VPN, restart the router, and switch to a public DNS resolver. Whichever step works tells you where the problem came from.
Does an NXDOMAIN error go away on its own?
Sometimes it does. If you just added a record or changed name servers, old caches expire and the site starts loading. However, if the domain expired or a record is missing, waiting will not help. First confirm the real cause with WHOIS and dig, and wait only when stale caches explain the error.
Can I get my site back if my domain expired?
Often yes, but the rules depend on the extension and your registrar. ICANN's policy defines renewal and recovery periods for generic domains, while country-code domains follow their own rules. Log in to your registrar account without delay and try to renew. If that fails, contact the registrar's support right away.
Is it safe to change DNS settings myself?
It is safe if you know what you are doing, but a wrong NS or MX change can take down your site and email. Before you edit, save a copy of the current records and lower the TTL. Then verify the new records with dig. For DNSSEC or email records, ask your hosting provider for help.
  • dns_probe_finished_nxdomain
  • NXDOMAIN
  • DNS error
  • DNS cache
  • name servers
  • domain expiry
  • Chrome errors
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.