PAC-X003 · dnsdomainis-without-leading-dot

dnsDomainIs pattern without a leading dot matches look-alike domains

high · Security and fail-safety · Top 20 #4

dnsDomainIs is a plain string-suffix test. "corp.example" matches www.corp.example, corp.example and also notcorp.example. Only ".corp.example" restricts the match to subdomains.

Why it matters

dnsDomainIs(host, domain) returns true when host ends with domain; it does not check for a dot boundary. With "corp.example" three unrelated relations collapse into one match: the apex corp.example, subdomains such as www.corp.example, and any domain whose name merely ends in those characters, e.g. notcorp.example or evilcorp.example (lab, 2026-05-20, with example.com as the pattern). The last group is attacker-registrable.

The leading dot fixes the boundary but also excludes the apex, so “domain and all subdomains” needs two clauses (see PAC-C009).

How to fix

Write dnsDomainIs(host, ".example.com") and add host == "example.com" if the apex should match too.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, "example.com")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "example.com" || dnsDomainIs(host, ".example.com")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumSuffix comparison without boundary check (helper library implementation).code, verified 2026-10-04 · ref
pacparserdnsDomainIs(host, "example.com") is true for a look-alike ending in "example.com", for example.com itself and for www.example.com.lab, verified 2026-05-20

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References