Troubleshooting
DNS_PROBE_FINISHED_NXDOMAIN: what it means and how to fix it
DNS_PROBE_FINISHED_NXDOMAIN means the domain name didn't resolve. How to tell a dead domain from a local DNS glitch, with fixes for site owners and visitors.
Updated · 6 min read
What DNS_PROBE_FINISHED_NXDOMAIN means
DNS_PROBE_FINISHED_NXDOMAIN means Chrome could not turn the domain name into an IP address, so it had nowhere to connect. NXDOMAIN is the DNS answer for "no such domain": the resolver looked the name up and was told it does not exist.
Chrome shows it on a "This site can't be reached" page, often with "server IP address could not be found". The "DNS probe" part refers to a quick test Chrome runs after a failed lookup to check whether your DNS setup works at all. When that probe succeeds, Chrome concludes the problem is the name itself rather than your connection. Lookups that fail for other reasons, such as broken DNSSEC, can end up on the same screen.
Check from outside your network first
The first question is whether the name fails everywhere or only for you. A DNS propagation check queries several public resolvers (Google, Cloudflare, DNS.SB and AdGuard) and compares their answers with the domain's authoritative nameserver.
If the authoritative nameserver has no record either, the problem is in the domain's DNS setup, and the site owner has to fix it. If the authoritative server answers correctly but some resolvers still return nothing, they are serving an old cached answer that will expire on its own. If every resolver answers correctly and only your device fails, the cause is local.
Causes for site owners
When the name fails for everyone, one of these is usually behind it:
- The domain expired. When registration lapses, the registrar typically stops the domain resolving or points it at a parking page within days.
- The domain is on hold. A clientHold or serverHold status removes the domain from DNS. Registrars apply holds for unpaid renewals, abuse reports, and contact email addresses that were never verified after registration or a contact change. A WHOIS or RDAP lookup shows the status.
- The record does not exist. A new subdomain, or www, was never added to the DNS zone, or a cleanup deleted it.
- The nameservers point at the wrong provider. After moving DNS, the registrar may list nameservers at a provider that does not hold the zone, or the zone was set up at one provider while the registrar still points at another.
- DNSSEC is broken. If DNSSEC was enabled at the old DNS provider and the DS record stays at the registrar after a move, validating resolvers such as Google and Cloudflare reject the answers and lookups fail.
- A typo in a record or in a link. A missing letter in a CNAME target, or in the link visitors click, produces a name that genuinely does not exist.
How site owners fix it
Work down the chain from the registrar to the record. Each step depends on the one before it.
- 1Look up the domain's registration status and expiry date. Renew an expired domain and clear any hold with the registrar, including verifying the registrant email if they ask for it.
- 2Check which nameservers the registrar lists for the domain, and confirm they belong to the DNS provider where you edit records.
- 3In that provider's zone, confirm an A record (and AAAA record if you use IPv6) or a CNAME exists for the exact name that fails, including www if visitors use it.
- 4If you changed DNS providers, check DNSSEC: either remove the DS record at the registrar or replace it with the one from the new provider.
- 5Run the DNS check again. When the authoritative nameserver returns the record, resolvers pick it up as their cached answers expire.
How visitors fix it
If the domain resolves fine from public resolvers, the stale or blocked answer is somewhere between your device and the internet. Try these in order:
- 1Check the spelling of the address, including the ending (.com, .co, .net).
- 2Load the site on another network, such as a phone on mobile data. If it works there, the problem is your network's DNS.
- 3Clear Chrome's own DNS cache: open chrome://net-internals/#dns and click "Clear host cache".
- 4Flush your operating system's cache. On Windows, run ipconfig /flushdns. On macOS, run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder.
- 5Restart your router, which also caches DNS answers.
- 6Switch to a different DNS resolver in your network settings, or in Chrome's "Use secure DNS" setting, and retry.
- 7Turn off VPNs, ad-blocking DNS services and parental-control filters. Some filtering services answer blocked domains with NXDOMAIN.
Why it fails for some people and works for others
Resolvers cache negative answers as well as positive ones. If someone looked up a name before its record existed, their resolver remembers "does not exist" for a period set by the zone's SOA record, often anywhere from minutes to hours. Until that cache expires, those visitors keep getting NXDOMAIN while everyone else sees the site.
That is why creating a record and immediately testing it can be misleading, and why a fix can appear not to work. The DNS check shows each resolver's answer side by side, so you can see whether the record is correct at the source and which resolvers have caught up.
Brand-new domains and records
A newly registered domain needs its nameservers set at the registrar and a zone with records at the DNS provider before it resolves. Registries usually publish new nameserver settings within minutes to hours, but a domain registered with the registrar's default parking nameservers and then switched can briefly answer from either side.
For a new record on an existing domain, the authoritative nameserver answers immediately once the record is saved. Resolvers that never asked about the name see it right away; only resolvers holding a cached "does not exist" answer lag behind. Testing a new name before creating its record is the usual way to trigger that delay.
Common questions
- How to fix DNS_PROBE_FINISHED_NXDOMAIN in Chrome?
- Check the spelling, clear Chrome's host cache at chrome://net-internals/#dns, flush your operating system's DNS cache, and try another DNS resolver. If the site fails on every network, the domain's DNS is broken and only the owner can fix it.
- Does DNS_PROBE_FINISHED_NXDOMAIN mean the domain has expired?
- Sometimes. An expired or suspended domain is a common cause, but a missing DNS record, wrong nameservers, a typo or a local DNS problem produce the same error. A registration lookup shows whether the domain is still active.
- Why does DNS_PROBE_FINISHED_NXDOMAIN appear on only one device?
- That device, or its network, is using a resolver with a stale or filtered answer. Flushing the DNS cache, restarting the router, or switching resolvers usually clears it.
- How long does it take for a new DNS record to stop showing NXDOMAIN?
- Resolvers that never asked about the name see it right away. Resolvers that already cached a "does not exist" answer keep it until the negative cache time from the zone's SOA record runs out.
- Is NXDOMAIN the same as a site being down?
- No. NXDOMAIN means the name could not be found in DNS, so the browser never contacted a server. A site that is down has working DNS but a server that does not answer or returns errors.
DNS propagation check
Four public resolvers vs. your own nameserver — has your change propagated?
Check your DNS recordsRelated guides
- How to check DNS propagation (and why it takes so long)Check DNS propagation by comparing public resolvers with your authoritative nameservers. Learn how TTL sets the timing and why changes seem stuck for hours.
- Multiple SPF records and too many DNS lookups: how to fixMultiple SPF records or over 10 DNS lookups make SPF fail with a permerror. How to merge records into one, count lookups and get back under the limit safely.
- How to fix a slow TTFB: server-side fixes that actually workSlow Time to First Byte is a server or network problem, not a page problem. Find the slow phase, then fix it with caching, a CDN, database work or hosting.
- Why is my website down? How to find the cause, step by stepFind out why your website is down: check if it's down for everyone, decode the error, and test the domain, DNS, SSL and server in the order that saves time.