Leading * without a dot matches look-alike domains
high
shExpMatch(host, "*corp.example") matches badcorp.example as well as www.corp.example. The safe form is "*.corp.example", where the dot forces a label boundary.
Why it matters
Without the dot, the leading wildcard can absorb part of a label. *corp.example is true
for www.corp.example, but also for badcorp.example and notcorp.example, which anyone
could register. This is the glob twin of PAC-X003. *.example.com requires at least one full
label before the dot and only matches real subdomains; the apex itself then needs its own
clause.
How to fix
Use "*.example.com" (with the dot) and add host == "example.com" for the apex.
Examples
Bad
function FindProxyForURL(url, host) {
if (shExpMatch(host, "*example.com")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (host == "example.com" || shExpMatch(host, "*.example.com")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| pacparser | "*example.com" matches a look-alike domain ending in "example.com"; "*.example.com" does not. | lab, verified 2026-05-20 |
Related rules
- dnsDomainIs pattern without a leading dot matches look-alike domains PAC-X003
- Trailing * in a host pattern matches attacker-controlled suffixes PAC-X002
- Wildcard inside a domain label PAC-X012