PAC-P003 · isresolvable-usage

isResolvable used as a reachability test

medium · Performance

isResolvable asks the resolver for an A record. It is a DNS round trip per request and answers a different question than "can I reach this host directly"; resolvable hosts can be unreachable and unreachable hosts can be cached as resolvable.

Why it matters

The usual intent is “if the name resolves internally, go direct”. That couples routing to the resolver (latency, outages, split-horizon surprises, poisoning) and is wrong on networks where every public name resolves too. The question “is this an internal host” is answered reliably by its domain suffix, not by whether the resolver knows it.

How to fix

Use domain suffix rules (dnsDomainIs(host, ".corp.example")) or isPlainHostName instead of isResolvable.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isResolvable(host)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References