The browser won't open and you just see a gray bar with the message DNS_PROBE_FINISHED_NXDOMAIN. The site worked yesterday, not today. You haven't touched any files and the hosting panel is green. This DNS error means exactly that the browser asked the DNS server "What is the IP of this domain?" and got the answer "No such domain exists." So the problem is either in the domain registration, the nameserver, or the cache. Until you separate these three, any change is just guesswork.
First, figure out whether the error is on your side or the domain's side
Before anything else, try from another network. A mobile phone with cellular data, or another server. If the site opens there, the problem is your local cache or your internet's DNS. If it doesn't open there either, the domain or nameserver is broken. This one test cuts the path in half.
Then from a Linux or macOS terminal, run this:
dig +short example.com A
dig +short example.com NS
dig +short example.com A @1.1.1.1
dig +short example.com A @8.8.8.8
The first line should return an IP. If it's empty, the domain doesn't exist in public DNS. The second line shows the registered nameservers; if it's ns1.yourhost.com but you've changed hosts, the error is found right here. Compare the third and fourth lines: if 1.1.1.1 answers but 8.8.8.8 doesn't, DNS propagation isn't finished yet and you need to wait.
On Windows, the equivalent is:
nslookup example.com 1.1.1.1
nslookup -type=NS example.com
The three real roots of the DNS_PROBE_FINISHED_NXDOMAIN error
The domain has expired and nobody knows
The most common cause, and the last thing you suspect. A domain that hasn't been renewed is removed from the zone and everything goes down overnight. Check with whois:
whois example.com | grep -i -E "expiry|expiration|status"
If you see a past date or clientHold, this isn't a DNS issue. It needs to be renewed. Note that in clientHold status, the domain appears active in your panel but doesn't exist in public DNS; this is what makes you search for nameservers for hours.
Wrong or incomplete nameserver registration
When you change hosts, you must change both nameservers in the registrar panel. If you change one and leave the other, some resolvers go to the old server and some to the new one. The result is intermittent errors: the site opens for you, not for your customer. Or it's open in the morning and not in the evening.
Another common mistake: registering a nameserver with an IP instead of a name. The NS record must be a name, not an IP. If you've put an IP in the nameserver field in the registrar panel, the zone will never be valid.
Local DNS cache and browser
If dig @1.1.1.1 gives the correct answer but your browser doesn't, it's a cache problem. The TTL of NS records is usually 24 hours and A records are between 300 and 3600 seconds. Until the TTL expires, the old resolver gives the old answer.
Clearing the cache:
# Linux with systemd-resolved
sudo resolvectl flush-caches
# Windows
ipconfig /flushdns
# macOS
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
In Chrome, also open chrome://net-internals/#dns and click Clear host cache. If you use a local DNS like Pi-hole or dnsmasq, restart that too.
This is where people go wrong
The biggest mistake I've seen: changing the nameserver and then immediately testing with their own browser. The site doesn't open, so they think they set the nameserver wrong and change it again. This restarts the TTL and delays the problem by several hours. The sign is that the site opens on a mobile phone with cellular data but not on the office laptop. This means your DNS is still old, not that the settings are wrong.
Second mistake: adding an A record in the registrar panel when the nameserver is on the host. That record has no effect because the zone is read from the host. You must make the change in the host's DNS zone, not in the domain panel.
The correct troubleshooting order
- Test from another network to rule out the local cache.
- Run
dig +shortwith a public resolver. - Run
whoisfor the domain's expiry and status. - Compare the registered nameservers with the host's nameservers.
- Check the A or CNAME record in the host's zone.
- If everything is correct, just wait for the TTL to expire.
A practical note: if you're on shared hosting and the server IP has changed, you may need to update the A record manually. In Linux hosting this is done from the management panel and doesn't require the registrar's involvement.
When the problem is on the server side, not DNS
Sometimes DNS answers correctly but the site doesn't open. Then the error changes: ERR_CONNECTION_TIMED_OUT or a white screen. If WordPress loads but the content doesn't, the story is different and you should go to WordPress white screen; diagnose and fix in ten minutes. If the site opens but is slow, it's not a DNS issue and WordPress speed optimization; a practical and actionable guide is the more correct path.
To make sure the outage wasn't DNS and the site is truly reachable from outside, set up website uptime monitoring; a practical guide for outage alerts without false errors. The difference between "DNS doesn't answer" and "the server doesn't answer" can only be distinguished with logs.
Practical summary
The DNS_PROBE_FINISHED_NXDOMAIN error has three roots and all three can be identified with one command. First dig with a public resolver, then whois, then comparing the nameservers. If all three are healthy, the problem is the cache and the solution is waiting, not changing settings. If the domain has expired, no DNS setting will save it.
Online DNS and record checking tools are also available in ServerNet's free tools and are useful for quick testing from multiple geographic locations. You can also see the technical documentation related to configuring zones and records in documentation and knowledge base.
Frequently asked questions
What does the DNS_PROBE_FINISHED_NXDOMAIN error mean?
It means the browser asked the resolver what the domain's IP is and received the answer "doesn't exist." This error has nothing to do with SSL, site files, or the hosting panel; it only says the domain name wasn't resolved in DNS.
Why does the site open on mobile but not on the laptop?
Almost always it means DNS cache. Your laptop is still holding the resolver's old answer and its TTL hasn't expired. Clear it with ipconfig /flushdns or resolvectl flush-caches, and if that doesn't work, temporarily set the system DNS to 1.1.1.1.
How long does it take for a nameserver change to take effect?
Between a few minutes and 48 hours, depending on the NS record's TTL, which is usually 24 hours. Until then, some users see the old site and some the new one. This is normal and you shouldn't change the settings again during this interval.
If the domain has expired, will changing the nameserver fix it?
No. An expired domain or one in clientHold status is removed from the zone and no DNS setting will bring it back. It must first be renewed in the registrar panel, then wait a few hours for full propagation.
Comments 0
No comments yet — be the first!