dnsDomainIs pattern without a leading dot matches look-alike domains
high
dnsDomainIs is a plain string-suffix test. "corp.example" matches www.corp.example, corp.example and also notcorp.example. Only ".corp.example" restricts the match to subdomains.
Why it matters
dnsDomainIs(host, domain) returns true when host ends with domain; it does not check
for a dot boundary. With "corp.example" three unrelated relations collapse into one match:
the apex corp.example, subdomains such as www.corp.example, and any domain whose name
merely ends in those characters, e.g. notcorp.example or evilcorp.example (lab,
2026-05-20, with example.com as the pattern). The last group is attacker-registrable.
The leading dot fixes the boundary but also excludes the apex, so “domain and all subdomains” needs two clauses (see PAC-C009).
How to fix
Write dnsDomainIs(host, ".example.com") and add host == "example.com" if the apex should match too.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, "example.com")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (host == "example.com" || dnsDomainIs(host, ".example.com")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | Suffix comparison without boundary check (helper library implementation). | code, verified 2026-10-04 · ref |
| pacparser | dnsDomainIs(host, "example.com") is true for a look-alike ending in "example.com", for example.com itself and for www.example.com. | lab, verified 2026-05-20 |
Related rules
- Leading * without a dot matches look-alike domains PAC-X004
- Domain matched exactly, subdomains not covered PAC-C009
- Very short or trailing-dot dnsDomainIs pattern PAC-C011