Wildcard characters in dnsDomainIs or localHostOrDomainIs
medium
dnsDomainIs and localHostOrDomainIs compare strings literally. "*.corp.example" is looked for as the literal characters *.corp.example, which no hostname contains.
Why it matters
Only shExpMatch understands * and ?. dnsDomainIs(host, "*.corp.example") asks whether
host ends with the eight characters *.corp.example; DNS names cannot contain *, so the
answer is always no. The branch is dead and traffic goes to the default route. The
confusion comes from mixing the two functions’ syntaxes.
How to fix
Use dnsDomainIs(host, ".corp.example") (plain suffix) or shExpMatch(host, "*.corp.example") (glob).
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, "*.corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | dnsDomainIs is a plain suffix comparison in the helper library. | code, verified 2026-10-04 · ref |
Related rules
- dnsDomainIs pattern without a leading dot matches look-alike domains PAC-X003
- Path, port or query characters in a host pattern PAC-C003