How to fix DNS_PROBE_FINISHED_NXDOMAIN

The browser asked DNS for the site’s address and was told the name does not exist. Check the spelling, your own DNS, then the domain itself.

3–5 minutes
Blue network cable with an RJ45 plug on a white background

DNS_PROBE_FINISHED_NXDOMAIN is Chrome’s message for “this domain name does not exist”. Your browser asked DNS for the site’s address, and the answer was NXDOMAIN: non-existent domain. Either the name is mistyped, your device’s DNS is giving a wrong answer, or the domain really has no DNS records: it has expired, its nameservers are wrong, or it was never set up.

Other browsers show the same problem differently: Firefox says Hmm. We’re having trouble finding that site, Safari says Safari Can’t Find the Server, and Edge shows DNS_PROBE_FINISHED_NXDOMAIN like Chrome.

Is it you or the site?

One test answers this. Ask a public DNS server directly:

nslookup example.com 1.1.1.1

On macOS and Linux, dig example.com @1.1.1.1 +short does the same. If it returns an IP address, the domain works and the problem is on your device or network: follow the visitor steps. If it says NXDOMAIN or Non-existent domain, the domain itself is broken: only its owner can fix it.

If you are visiting the site

Work down this list and reload the page after each step.

  1. Check the spelling, including the ending: .com and .co are different domains.
  2. Try another network. Load the site on your phone using mobile data. If it works there, the problem is your Wi-Fi network or device.
  3. Clear your DNS cache. Your computer may be holding an old “does not exist” answer. On Windows, open Command Prompt and run ipconfig /flushdns. On a Mac, open Terminal and run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder. In Chrome, also visit chrome://net-internals/#dns and click Clear host cache. See how to flush your DNS cache for other systems.
  4. Switch off VPNs, ad blockers and security software for a moment. Some block domains on purpose and answer NXDOMAIN for them. Pi-hole and similar network blockers do the same.
  5. Check the hosts file. An entry for the domain overrides DNS. It lives at C:\Windows\System32\drivers\etc\hosts on Windows and /etc/hosts on Mac and Linux.
  6. Use a public DNS server. Your internet provider’s DNS may be faulty. Set your device or router to use 1.1.1.1 (Cloudflare) or 8.8.8.8 (Google), then flush the cache again.
  7. Restart the router. It caches DNS answers too.

If the nslookup test above failed, none of these will help: the domain is broken for everyone.

If you run the site

The domain is returning NXDOMAIN worldwide. Check these in order.

1. Has the domain expired?

Expired domains stop resolving, usually within days. Check the registration:

whois example.com | grep -iE "expir|status"

A status such as clientHold, serverHold or redemptionPeriod, or an expiry date in the past, means the registrar has suspended it. Renew it at your registrar. clientHold can also mean the registrar is waiting for you to verify your contact email, which is common with new domains: look for their verification email.

2. Are the nameservers right?

The registry lists which nameservers answer for your domain. Ask it:

dig NS example.com +short
dig NS example.com @a.gtld-servers.net

The second command asks the .com registry directly (other endings have their own registry servers). The nameservers listed must be the ones where your DNS records actually live, such as your DNS host, Cloudflare or your web host. After changing DNS provider, the most common mistake is updating the records at the new provider but leaving the old nameservers at the registrar, or the reverse. See what a nameserver is.

3. Do the nameservers have the records?

Ask the domain’s own nameserver directly, which skips every cache:

dig example.com @ns1.your-dns-host.com
dig www.example.com @ns1.your-dns-host.com

If it answers NXDOMAIN or REFUSED, the zone does not exist on that server, or it has no record for that name. Add an A record for the bare domain and an A or CNAME record for www. See how to point a domain to a server.

A common case: the bare domain works but www gives NXDOMAIN, because only one of the two records was created.

4. Is DNSSEC broken?

If DNSSEC is switched on at the registrar but the DNS host is not signing the zone, or the keys changed during a move, validating resolvers such as 1.1.1.1 and 8.8.8.8 refuse the answers. Visitors usually see this as a failure to resolve. Check:

dig example.com +dnssec @1.1.1.1

SERVFAIL here, while dig example.com +cd @1.1.1.1 (checking disabled) works, means DNSSEC is broken. Remove the DS record at the registrar, or publish the correct one from your DNS host.

5. Just registered or just moved?

A newly registered domain, or one whose nameservers just changed, can take a few hours to resolve everywhere, and resolvers that already cached the NXDOMAIN answer keep it for as long as the zone’s negative cache time, often up to an hour. See what DNS propagation is.

Confirm it is fixed

dig example.com @1.1.1.1 +short
dig example.com @8.8.8.8 +short

Both should return your server’s IP address. Then flush your own DNS cache and load the site.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.