You type an address, press Enter, and Chrome replies with "This site can't be reached" and the code DNS_PROBE_FINISHED_NXDOMAIN. Edge and other Chromium browsers show the same code; Firefox says "Hmm. We're having trouble finding that site." The message looks alarming, but it describes one specific thing, and once you know what it is the fix is usually quick.
What the error actually says
NXDOMAIN is a DNS response code meaning non-existent domain. Your browser asked a DNS resolver for the address of the name you typed, and the answer came back: that name does not exist. The browser then ran its own checks (the "probe") and finished with the same conclusion.
That answer can be true or false:
- It is true when the domain has expired, was never registered, was typed wrongly, or the subdomain has no DNS record.
- It is false when something between you and the internet gives a wrong answer: a stale cache, a misbehaving resolver, a VPN, security software or an edited hosts file.
The first job is working out which of the two you are dealing with.
Step 1: is it just you?
Try the same address from a different network, for example a phone on mobile data with Wi-Fi turned off. Then check the name from outside your network with our DNS lookup tool or the DNS propagation checker, which asks public resolvers around the world.
- If public resolvers return an address, the domain is fine and the problem is on your device or network. Go to the device fixes below.
- If public resolvers also return NXDOMAIN, the domain itself has a problem. Go to the domain fixes.
Fixes when the problem is your device or network
Check the spelling
It sounds obvious, but a missing letter or a wrong ending (.co instead of .com) is the most common cause of a genuine NXDOMAIN.
Flush the DNS caches
Your operating system and browser both keep a short cache of DNS answers, including negative ones. If you visited the name before it existed, the "does not exist" answer may still be cached.
# Windows (Command Prompt as administrator)
ipconfig /flushdns
# macOS
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
# Linux with systemd-resolved
resolvectl flush-caches
In Chrome you can also open chrome://net-internals/#dns and click "Clear host cache".
Try a different DNS resolver
Internet providers' resolvers sometimes fail or lag behind. Switching your device or router to a public resolver such as 1.1.1.1, 8.8.8.8 or 9.9.9.9 is a quick test. If the site loads afterwards, the original resolver was the problem.
Turn off the VPN, proxy or filtering software
VPNs route DNS through their own servers, and some security suites and parental-control tools deliberately answer NXDOMAIN for sites they block. Disable them briefly to test.
Check the hosts file
The hosts file overrides DNS for any name listed in it. On Windows it lives at C:\Windows\System32\drivers\etc\hosts; on macOS and Linux at /etc/hosts. Remove any leftover line for the domain, for example one added while testing a new server.
Restart the router
Home and office routers often run their own small DNS cache. A restart clears it and renews the connection to your provider.
Fixes when the domain itself returns NXDOMAIN
Has the domain expired?
An expired domain is removed from the zone after a grace period, and every resolver then answers NXDOMAIN. Look the domain up with the WHOIS lookup and check the expiry date and status. Statuses such as clientHold, serverHold or redemptionPeriod mean the registry has taken the name out of DNS, usually because a renewal or verification is outstanding.
Are the name servers right?
If the domain's name servers at the registrar point to a DNS host that has no zone for it, that host will answer NXDOMAIN or refuse to answer. This often happens after moving DNS providers or cancelling an old hosting account. Compare the NS records shown in WHOIS with the provider where you actually manage your records.
Does the record exist?
For a subdomain such as shop.example.com, the main domain can work perfectly while the subdomain has no A, AAAA or CNAME record at all. Add the record at your DNS host. If a CNAME points to another name, check that the target exists too; a CNAME to a deleted name produces the same error.
Was the record created only minutes ago?
Resolvers cache "does not exist" answers as well, for the time set in the zone's SOA record. If someone looked the name up before you created it, they may keep seeing NXDOMAIN for a while. This clears on its own; flushing local caches and checking from a public resolver helps confirm it.
Quick reference
| What you see | Likely cause | Fix |
|---|---|---|
| Fails only on one device | Local cache, hosts file, VPN | Flush caches, check hosts, disable VPN |
| Fails on one network only | Router or provider resolver | Restart router, switch to a public resolver |
| Fails everywhere, WHOIS shows hold or expiry | Domain expired or suspended | Renew or complete verification at the registrar |
| Fails everywhere, domain active | Wrong name servers or missing record | Fix delegation or add the record |
Key takeaways
- DNS_PROBE_FINISHED_NXDOMAIN means a resolver said the name does not exist.
- Check from outside your network first to see whether the problem is local or global.
- Local problems are fixed with cache flushes, a different resolver or removing VPN and hosts-file overrides.
- Global problems usually mean an expired domain, wrong name servers or a missing DNS record.