PAC-B007 · dot-local-direct

*.local routed direct

info · Best practice and maintainability

Routing *.local direct is right where .local is reserved for mDNS/Bonjour. Older enterprises still use .local as their internal DNS suffix; there the rule is also right, but it must be a deliberate decision rather than a template copy.

Why it matters

RFC 6762 reserves .local for multicast DNS, and templates (including public vendor templates) send it DIRECT for that reason. Many Active Directory forests created before 2013 use .local as their domain suffix and resolve it via unicast DNS. The DIRECT rule is still usually correct for them (internal hosts should not go via the proxy), but the author should know which case applies and whether the proxy must reach those hosts for some reason. Informational.

How to fix

Confirm whether .local is mDNS-only or your AD suffix, and comment the rule accordingly.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*.local")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  // .local is mDNS only on this network (AD suffix is corp.example)
  if (shExpMatch(host, "*.local") || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References