How to Fix DNS_PROBE_FINISHED_NXDOMAIN

Your browser can't turn the hostname into an IP. Here's the fix order.

DNS_PROBE_FINISHED_NXDOMAIN means the domain doesn't resolve. Flush DNS, check hosts file, DNS server, VPN, and firewall.

What DNS_PROBE_FINISHED_NXDOMAIN means

This Chrome error means the browser asked a DNS resolver for the domain and got back NXDOMAIN — "this domain does not exist." It's a DNS-level failure that happens before any connection to your server is attempted. The site might be perfectly up; the problem is that the hostname can't be resolved to an IP address.

NXDOMAIN can be caused by a real DNS misconfiguration (the domain's records are actually wrong) or by a local issue (stale DNS cache, a bad hosts file, an overzealous VPN or firewall). The first step is always to determine whether the problem is global or just you: try the site from a different network or a tool like `dig` against a public resolver like 1.1.1.1.

Local fixes: flush DNS, hosts file, DNS server

Start by flushing your local DNS cache. On Windows, run `ipconfig /flushdns`; on macOS, `sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder`; on Linux, restart systemd-resolved or nscd. A stale negative cache entry (from when the domain was briefly misconfigured) can persist for the TTL duration and clearing it forces a fresh lookup.

Next, check your hosts file (`C:\Windows\System32\drivers\etc\hosts` on Windows, `/etc/hosts` on macOS/Linux) for a stale or wrong entry pointing the domain at an old IP. Then try switching your DNS resolver to a public one (1.1.1.1 or 8.8.8.8) — if the site loads with a public resolver but not your default, your ISP or network's DNS is the problem.

Network fixes: VPN, firewall, and real DNS issues

If you're on a VPN, disconnect and retry — corporate VPNs often route DNS through an internal resolver that may not have the domain or may block it. Firewalls and security software (and some "parental control" DNS filters) can return NXDOMAIN for domains they block, mimicking a real DNS failure. Temporarily disable them to test.

If the problem is global (the domain doesn't resolve from anywhere), it's a real DNS issue: the domain expired, the nameservers changed, or the A/AAAA record was deleted. Log into your DNS provider and verify the records exist and point at the right IP. DNS propagation after a change can take minutes to hours depending on TTL. SurePing doesn't currently offer DNS-record monitoring (we monitor HTTP, keyword, ping, port, SSL, and heartbeat), so for DNS record changes you'll want a dedicated DNS monitoring tool alongside us.

Related