Name
nxdomain-redirect
Syntax
nxdomain-redirect <suffix>;
Blocks
Default value(s)
None
Introduced
- Date: 2016-03-25
- BIND version: 9.11.0a1
Deprecated
Still current as of 2026-10-07, but it will be deprecated in a future release.
Removed
N/A
Description
This option causes a resolver to append <suffix> to the query name, if the first attempt to find an answer for the QNAME itself results in an NXDOMAIN response. BIND will then try to resolve the new QNAME and give that answer to the client.
The goal of this option is to allow resolver operators to redirect queries that (for instance) may be misspelled to a safety server, that may host a web page indicating to the client that they have made a typo.
Typical usage is shown below.
...
options {
...
nxdomain-redirect example.com;
...
...
};
...
It works as follows:
- A client makes (say) an A query to the resolver for
www.mydoman.com. Note thatmydomainis missing the letteri. - The resolver attempts to find an answer for this name/type but fails, receiving NXDOMAIN from an upstream server.
- The resolver appends
example.comto the original query name, now making itwww.mydoman.com.example.comand initiates a fetch for this new name. - Assuming the administrators of this server own
example.comthe resolver will fetch the answer for this new name, possibly by using a wildcard in that zone, and return the address to the client. - The client connects to that address. What happens next is outside the realm of DNS. But clients are often web browsers, so the returned address may be a web server hosting a page informing the end user of their spelling mistake.
nxdomain-redirect was introduced as a more fine-grained approach to NXDOMAIN redirection than the existing redirect zone type. From the CHANGES notes:
An additional NXDOMAIN redirect method (option "nxdomain-redirect") has been added, allowing redirection to a specified DNS namespace instead of a single redirect zone.
If both redirect zones and nxdomain-redirect are configured and a client query could possibly match either of them, redirect zones take precedence.
Limitations
nxdomain-redirect works for ordinary record types only. That is, types that do not cause any additional processing. Some examples of these are A, AAAA and PTR.
Examples of types that do cause additional processing, and thus will not be processed by this feature, are NS, SRV and NAPTR
NXDOMAIN redirection also won't work if the client making the original query has set DO=1, indicating that they may want to perform DNSSEC validation themselves. If that is true, NXDOMAIN redirection will be skipped and the resolver will pass the NXDOMAIN response it received - which may itself be DNSSEC-signed - to the client as is.
ARM reference
This statement/block is defined in the Administrator Reference manual (ARM) here
See also...
BIND 9.9 redirect zones (for NXDOMAIN redirection)
NXDOMAIN Redirection Using DLZ in BIND 9.10 and later
Zone type "redirect"
