Very short or trailing-dot dnsDomainIs pattern
medium
Patterns like ".uk." (trailing dot) or ".ab" are suspicious. A trailing dot never matches the host as engines pass it; a two-letter suffix without a label is a TLD or a typo.
Why it matters
Engines pass host without a trailing dot, so dnsDomainIs(host, ".uk.") is always false.
A pattern of only a few characters (.ab, .x) is either a TLD match (PAC-X005) or a
truncated domain. Both make the branch dead or far too broad.
Draft: the exact handling of trailing dots in host (and of hosts written with a trailing
dot in the URL) needs a lab matrix across Chromium, Firefox and WinHTTP before this rule is
promoted.
How to fix
Use a full domain suffix such as ".corp.example" without a trailing dot.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".example.")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- Pattern matches an entire top-level domain PAC-X005
- dnsDomainIs pattern without a leading dot matches look-alike domains PAC-X003