Browser with broken connection chain failing to reach DNS servers, magnifying glass inspecting the break

What DNS_PROBE_FINISHED_NXDOMAIN means

Seeing dns_probe_finished_nxdomain in Chrome means one thing: your browser asked "where is this website?" and DNS answered "that name doesn't exist." Without an IP address there is nothing to connect to. The good news: this is one of the most fixable errors on the web — once you know whether the fault is your device or the domain itself, the fix is usually minutes away.

The code breaks down neatly: DNS_PROBE_FINISHED means Chrome's lookup completed (not a timeout), and NXDOMAIN is DNS-speak for "non-existent domain." But it often isn't true — the domain may be fine, and only your device is getting the wrong answer. Here's how to tell the difference.

How a domain lookup works — and where dns_probe_finished_nxdomain is born

Follow what happens in the half-second after you press Enter. Your browser works down a chain, and each link can fail in its own way:

  1. Browser cache. Chrome keeps its own short-term memory of recent lookups. A remembered bad answer means it never asks anyone else.
  2. Your operating system. The OS has its own DNS cache plus a hosts file — a local override list checked before any network query.
  3. The recursive resolver. Usually your ISP's server, your router, or a public one like 1.1.1.1. It does the real work: asking root servers which servers handle the domain's ending, then those TLD servers for the domain's nameservers, then the domain's own nameserver for the IP.
  4. The authoritative nameserver. The domain owner's DNS host — and where NXDOMAIN is born. If the name truly has no records here, that answer travels back up the whole chain to your browser.

The twist most guides skip: NXDOMAIN answers get cached too. Resolvers store the negative answer — typically for the duration in the domain's SOA record — and keep serving it. This "negative caching" is why the error can linger after records are fixed, and why clearing caches works so well. Cloudflare's official troubleshooting docs describe the same mechanics from the operator's side.

DNS resolution chain from browser to authoritative server

The 30-second diagnosis: is it you, or the domain?

Every fix depends on one question: does the domain resolve for the rest of the internet, or only fail on your device? Your own browser can't answer that — it's the suspect. Instead, run a free DNS lookup, which asks public DNS servers instead of your device:

  • Resolves everywhere else: the site is up; something on your device or network feeds you a wrong answer. See the device-side causes below.
  • Resolves nowhere: everyone sees the error — the fix sits with whoever controls the domain. Jump to the owner checklist.

This one test prevents the classic mistakes: flushing caches for a domain that expired yesterday, or waiting days for "propagation" when your VPN is the real culprit.

When it's your device: causes and why each fix works

If the domain resolves for the world but not for you, the wrong answer is manufactured somewhere between your browser and the internet:

Stale caches at three layers. Browser, OS, and router each cache DNS answers — including wrong ones. Clearing all three forces a fresh query up the chain, which is why this fixes the error more often than anything else.

Your DNS server itself is broken. If your ISP's resolver is down or a captive portal on public Wi-Fi is intercepting queries, every answer is suspect. Switching to 1.1.1.1 or 8.8.8.8 routes around the broken middleman.

VPN, proxy, or DNS-filtering apps. These reroute DNS through their own servers by design. If those servers are slow or misconfigured, you get NXDOMAIN for a site that works fine without them — disabling the VPN momentarily reveals it instantly.

A hosts file entry. The hosts file is checked before any DNS query leaves your machine, so one stale or malicious line overrides the entire internet. Check it when every other device on your network loads the site fine.

Chrome's own quirks. Chrome keeps a separate internal DNS cache and experimental flags that can break resolution on their own. Clearing its host cache and resetting flags fixes the browser layer without touching your system. Bluehost's troubleshooting walkthrough covers these browser-level steps if you want a second reference.

Lookalike errors: which one do you actually have?

Chrome shows several similar errors, and treating the wrong one wastes time:

Error code What it actually means First step
DNS_PROBE_FINISHED_NXDOMAIN The resolver answered: this name doesn't exist Run a DNS lookup — resolves means your device, NXDOMAIN means the domain
ERR_NAME_NOT_RESOLVED The browser couldn't resolve the name but couldn't confirm why Same diagnosis as above; try switching DNS servers first
DNS_PROBE_FINISHED_BAD_CONFIG Your device's DNS configuration itself is broken Check network/DNS settings, renew the connection, restart the router
ERR_CONNECTION_TIMED_OUT DNS worked and found the server, but it never answered Not a DNS problem — check which host the domain points to with an IP address lookup

When it's the domain: owner checklist

If the domain doesn't resolve anywhere, the fix belongs to whoever controls it. Most cases end at one of the first three:

  1. Check the exact name. A missing www subdomain is the most common domain-side cause: the root has an A record but nobody created one for www. Add it as a CNAME to the root.
  2. Confirm the domain is registered and active. Expired, suspended, or never-registered domains return NXDOMAIN by default — and auto-renew fails more often than people expect.
  3. Verify the nameservers. The registrar must point at the nameservers of whoever hosts the DNS. After moving DNS hosts, mismatched nameservers are the classic cause.
  4. Check the records. The root needs an A (or AAAA) record; subdomains need their own. A CNAME pointing at a deleted service also produces NXDOMAIN.
  5. Allow for propagation — then verify. New records usually work within minutes, but resolvers hold cached answers until their TTL expires; nameserver changes can take 48 hours. FrostRank's DNS lookup shows each record's TTL so you know exactly how long the wait is.
  6. Check DNSSEC. Moving DNS providers with DNSSEC still enabled at the registrar invalidates the new setup via the old DS record. Remove or update it.

For domains recently moved to Cloudflare, their community troubleshooting tip lists the Cloudflare-side checks worth ruling out.

Frequently asked questions

Why does Chrome show DNS_PROBE_FINISHED_NXDOMAIN but Firefox shows a different message?
Each browser phrases the same DNS failure differently — Firefox says the server could not be found, Edge can't reach the page, Safari can't find the server. Cause and fixes are identical; only the wording changes.

Can this error appear when the website is actually online?
Constantly. The error describes what your device was told, not the site's true state. If public DNS resolves the domain, the site is up and the wrong answer comes from your cache, DNS server, VPN, or hosts file.

I fixed my DNS records — why do I still see the error?
Negative caching. Resolvers stored the earlier "doesn't exist" answer and serve it until its TTL expires. Wait out the TTL, or test from a network that never cached it — mobile data is a handy check.

Does clearing my browser cache fix it?
Clearing images and cookies doesn't touch DNS. You must clear DNS specifically: Chrome's host cache, your OS DNS cache, and ideally your router's. A stale entry in any one keeps the error alive.

Is DNS_PROBE_FINISHED_NXDOMAIN caused by a virus?
Usually not — but DNS-hijacking malware is a real, if uncommon, cause. If every site fails and your DNS settings changed without your knowledge, check the hosts file and reset to a trusted public DNS provider.

Why does the error appear and disappear on its own?
Intermittent NXDOMAIN usually means a flaky link: an overloaded ISP resolver, a captive portal answering queries before login, or a VPN whose DNS drops under load. Switching to 1.1.1.1 or 8.8.8.8 typically ends it.