PAC-C004 · dnsdomainis-with-glob

Wildcard characters in dnsDomainIs or localHostOrDomainIs

medium · Correctness

dnsDomainIs and localHostOrDomainIs compare strings literally. "*.corp.example" is looked for as the literal characters *.corp.example, which no hostname contains.

Why it matters

Only shExpMatch understands * and ?. dnsDomainIs(host, "*.corp.example") asks whether host ends with the eight characters *.corp.example; DNS names cannot contain *, so the answer is always no. The branch is dead and traffic goes to the default route. The confusion comes from mixing the two functions’ syntaxes.

How to fix

Use dnsDomainIs(host, ".corp.example") (plain suffix) or shExpMatch(host, "*.corp.example") (glob).

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumdnsDomainIs is a plain suffix comparison in the helper library.code, verified 2026-10-04 · ref

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References