PAC-C011 · dnsdomainis-short-pattern

Very short or trailing-dot dnsDomainIs pattern

medium · Correctness

Patterns like ".uk." (trailing dot) or ".ab" are suspicious. A trailing dot never matches the host as engines pass it; a two-letter suffix without a label is a TLD or a typo.

Why it matters

Engines pass host without a trailing dot, so dnsDomainIs(host, ".uk.") is always false. A pattern of only a few characters (.ab, .x) is either a TLD match (PAC-X005) or a truncated domain. Both make the branch dead or far too broad.

Draft: the exact handling of trailing dots in host (and of hosts written with a trailing dot in the URL) needs a lab matrix across Chromium, Firefox and WinHTTP before this rule is promoted.

How to fix

Use a full domain suffix such as ".corp.example" without a trailing dot.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".example.")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References