isResolvable used as a reachability test
medium
isResolvable asks the resolver for an A record. It is a DNS round trip per request and answers a different question than "can I reach this host directly"; resolvable hosts can be unreachable and unreachable hosts can be cached as resolvable.
Why it matters
The usual intent is “if the name resolves internally, go direct”. That couples routing to the resolver (latency, outages, split-horizon surprises, poisoning) and is wrong on networks where every public name resolves too. The question “is this an internal host” is answered reliably by its domain suffix, not by whether the resolver knows it.
How to fix
Use domain suffix rules (dnsDomainIs(host, ".corp.example")) or isPlainHostName instead of isResolvable.
Examples
Bad
function FindProxyForURL(url, host) {
if (isResolvable(host)) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- DNS lookup on every request PAC-P001