DNS_PROBE_FINISHED_NXDOMAIN This means the browser completed a DNS query and received a response indicating that the requested name does not exist. The cause could be the visitor's device or network, but also missing records, incorrect nameservers, misconfigured DNSSEC, or a negative response that is still cached.You try to open a website and Chrome displays "This site cannot be accessed" accompanied by the code DNS_PROBE_FINISHED_NXDOMAIN. The message looks technical, but it describes a very specific problem: before connecting to the server, the browser failed to convert the entered domain into a valid IP address.
The correct solution depends on who is experiencing the error. If only one person is unable to access the site and the domain is working from other networks, the device, browser, router, or DNS resolver should be checked. If no one can log in, the site owner should inspect the domain, nameservers, and DNS zone. Changing settings randomly can prolong the outage or affect email.
This guide explains what the error means, how to isolate its cause, and what to do step by step, whether you are visiting a page or managing the site.
What does DNS_PROBE_FINISHED_NXDOMAIN mean?
DNS is the system that links easy-to-remember names, such as example.com, with the addresses used by the servers. When you type a URL, the device queries a DNS resolver. This resolver can respond from its cache or query the servers responsible for the domain until it finds the corresponding record.
DNS_PROBE_FINISHED indicates that the check is finished. NXDOMAIN means non-existent domainAccording to the resolver, the queried name does not exist. The documentation for Cloudflare on DNS_PROBE_FINISHED_NXDOMAIN It defines it as a completed query with no records associated with the requested name.
This is not the same as a 404 error. A 404 error occurs after reaching a web server, when the server cannot find a route or resource. In NXDOMAIN, the connection doesn't even reach the server because the name cannot be resolved.

Most common causes of the error
1. The domain or subdomain is misspelled.
A single incorrect letter, hyphen, or ending is enough to find a name that doesn't exist. It can also fail on its own. www, store or any other subdomain if it does not have its own record, even if the root domain works.
2. Missing A, AAAA, or CNAME records
The domain may be registered and use valid nameservers, but lack the record that connects the name to the hosting. For a website, the root domain and the variant are usually checked. www. A CNAME also fails if its destination does not exist or does not resolve.
3. The nameservers do not match the DNS provider
The records may be perfectly created in a control panel that is no longer authoritative. This happens when migrating hosting providers, activating a CDN, or changing DNS providers without properly updating the nameservers at the registrar.
4. There is an inconsistent DNSSEC configuration
DNSSEC adds cryptographic validation to DNS responses. If the registrar retains an older DS record while the zone uses different keys, validation can fail. This scenario typically returns SERVFAIL, However, it is advisable to review it within any post-migration diagnosis.
5. There is a cached NXDOMAIN response
Resolvers also store negative responses. If someone queried a subdomain before the record existed, they may continue to receive NXDOMAIN for the period defined by the zone. negative cache documentation It explains that lowering the TTL of the new record does not remove a negative response already stored.
6. The problem is with the device or the network
An outdated local cache, an unstable router, a VPN, a proxy, antivirus software, or your internet service provider's resolver can affect the connection. In that case, the website might work using mobile data, another network, or a public resolver.
Quick diagnosis before changing anything
- Check the URL. Check domain, extension, and subdomain.
- Try another page. If no domain opens, it's probably not a problem with the site.
- Switch networks. Compare Wi-Fi and mobile data.
- Try another device. This separates a local fault from a network fault.
- Check the DNS. Use
nslookupodigto review the answer. - Ask more than one solver. Compare the provider's DNS to 1.1.1.1 or 8.8.8.8.
Avoid starting by deleting the DNS zone or changing nameservers. First, determine if the error affects a user, a network, a resolver, or all visitors.
How to fix DNS_PROBE_FINISHED_NXDOMAIN as a visitor
1. Reload and restart your browser
Close your browser completely and reopen it. Also, try a private browsing window to rule out extensions or session statuses. If the problem only occurs in one browser, check its secure DNS, extensions, VPN, and proxy settings.
2. Restart the device and the router
A restart refreshes network processes and connections that may have become corrupted. Unplug your router for a few seconds, plug it back in, and wait for it to reconnect before trying again.
3. Clear the local DNS cache
In Windows, open a terminal with administrative privileges and run:
ipconfig /flushdns
On macOS, the command depends on the system version. In current versions, the following is commonly used:
sudo dscacheutil -flushcache; sudo killall -HUP mDNSReply
Clearing the local cache only affects the device. If the provider's resolver continues to respond negatively, you'll have to wait for it to expire or temporarily query another DNS service.
4. Refresh network settings
In Windows you can release and renew the DHCP assigned address with ipconfig /release y ipconfig /renew. Only do this if you know the impact on your active connection.
5. Temporarily disable VPN, proxy, or DNS filters
A corporate VPN, parental controls, or security tool might use a different resolver. Disable it only during testing and re-enable it afterward. If the domain works without that service, review its rules instead of keeping it disabled.
6. Try a public DNS resolver
You can temporarily configure a service like Cloudflare 1.1.1.1 or Google Public DNS 8.8.8.8. If the page loads, the problem might be with the resolver mentioned earlier. This isn't a solution for missing authoritative records: if the domain is misconfigured, it will eventually fail with all of them.

How to fix the error if you are the site owner
1. Confirm that the domain is active
Check the expiration date and status with the registrar. An expired, suspended, or pending verification domain may stop resolving. Also, confirm that you are managing the exact name and not a variant.
2. Check the published nameservers
Execute dig NS yourdomain.com Or use a DNS lookup tool. Compare the response with the nameservers provided by your provider. If they don't match, edit them at the registrar, not within your hosting control panel.
3. Review the authoritative zone
Verify that there is a record for the root domain and another for each subdomain used. The A record must point to a valid IPv4 address; AAAA to an IPv6 address; and the CNAME to a resolvable hostname. Do not copy values from a tutorial; use those provided by the hosting provider or service.
4. Check the destination directly
Ask the authoritative nameserver to avoid recursive caches:
dig @nameserver-autoritativo.com yourdomain.com A
If the authoritative server returns the correct record but other resolvers still respond with NXDOMAIN, there is likely negative caching. If they also don't return it, the zone is still incomplete or you are editing the wrong provider.
5. Audit DNSSEC before and after a migration
Compare the registrar's DS record with the keys published by the DNS provider. When switching nameservers, follow the order recommended by both providers. Don't routinely remove DNSSEC if it's working; only correct the string after you've confirmed the inconsistency.
6. Protect your email too
When rebuilding a zone, don't forget MX, SPF, DKIM, DMARC, and verification records. Recovering the website by deleting mail records can create a second outage. Before editing, export or document the current state.

How long does it take for the error to disappear?
A local fault can be resolved immediately by clearing the cache or switching networks. A fix in the authoritative zone may start appearing within minutes, but resolvers that stored NXDOMAIN wait for the negative cache period to expire. The propagation may appear jagged because each resolver queried the domain at a different time.
Consult the SOA log to estimate the remaining TTL of the negative response. The behavior is defined in the RFC 2308 on DNS Negative Cache. During this time, avoid repeatedly changing nameservers or registers: each additional modification makes it harder to know which configuration is being evaluated.
Mistakes to avoid
- Change nameservers without backing up existing records.
- Confusing NXDOMAIN with a server crash or a 404 error.
- Delete MX or TXT records when attempting to recover the website.
- Disable antivirus, firewall or DNSSEC permanently without diagnostics.
- Create a record just for
wwwand forget the root domain, or vice versa. - Assuming that lowering the TTL eliminates a negative response already stored.
- Evaluate propagation with a single tool or network.
Final checklist
- The domain is active and spelled correctly.
- The registrar's nameservers correspond to the current provider.
- The root domain and the subdomains used have records.
- A, AAAA or CNAME destinations are valid.
- DNSSEC has a consistent chain.
- The mail records remain intact.
- The authoritative answer is correct.
- It was verified from more than one resolver and one network.
If you manage the site and are preparing a new website or a migration, document who controls the domain, DNS, and hosting before launch. Our guide to plan domain, hosting and publishing of a website It places these checks within the complete process and helps to coordinate them without improvising changes during an incident.
Frequently Asked Questions about DNS_PROBE_FINISHED_NXDOMAIN
Does DNS_PROBE_FINISHED_NXDOMAIN mean that the server is down?
Not necessarily. The error occurs before reaching the server: the name could not be resolved. The hosting may be functioning even if the DNS or nameserver records are incomplete.
Why does the website work with mobile data but not with Wi-Fi?
Each network may use different resolvers and caches. Wi-Fi might retain a negative response or use a faulty DNS, while the mobile network is already receiving the correct record.
Does clearing the browser cache fix NXDOMAIN?
It can help if the state is stored locally, but it doesn't correct missing records or clear the negative cache of an external resolver. You must first identify where the response originates.
How long does DNS propagation take?
It depends on the TTL and previous caches. Authoritative servers can update quickly, but a resolver that saved NXDOMAIN will wait for the negative TTL specified by the zone to expire.
Does switching to 1.1.1.1 or 8.8.8.8 always fix the error?
No. You can avoid an outdated local resolver, but if the name doesn't exist on the authoritative servers, any DNS will end up returning the same result.
Does an expired SSL certificate produce NXDOMAIN?
No. The browser validates the certificate after resolving the domain and establishing the connection. An SSL problem generates a different message; NXDOMAIN pertains to DNS resolution.
Do I need to change the nameservers to fix this?
Only proceed if you've confirmed they're pointing to the wrong provider. If they're already correct, the problem might be in the zone logs or the cache. Changing them without diagnosis could worsen the outage.
Conclusion
DNS_PROBE_FINISHED_NXDOMAIN There's no single solution. First, determine if the problem lies with a device, a network, a resolver, or the authoritative configuration. Then, apply the smallest change that corrects the cause and verify from multiple points.
If the error affects your company's website and you need to recover the resolution without compromising the website or email, our team at web development You can check domain, hosting, DNS and publishing as a single system.