Exact error diagnosisReviewed 2026-08-13By HostWithShery technical editorial

NS_ERROR_UNKNOWN_HOST

Firefox networking reports NS_ERROR_UNKNOWN_HOST when lookup of the hostname fails. Treat it as a name-resolution symptom first, not as an SSL, redirect or application-response error.

Start with evidence from your own domain before changing DNS, SSL or mail settings.
Check your own configuration

SSL Certificate Checker

This page is preconfigured with the SSL Certificate Checker that best matches this problem.

No accountPublic evidence only
Live public check
No account · Public configuration only
On this page

What this error means

Firefox networking reports NS_ERROR_UNKNOWN_HOST when lookup of the hostname fails. Treat it as a name-resolution symptom first, not as an SSL, redirect or application-response error. The browser or proxy message describes the symptom, not necessarily the root cause. HostWithShery therefore checks the TLS, certificate and HTTPS evidence that can be observed publicly before recommending a configuration change.

Most likely causes

These are the first explanations to test because each can produce this exact symptom. Treat them as hypotheses until the matching public evidence is present.

  • Requested hostname has no usable DNS answerVerify requested hostname has no usable DNS answer from the public Internet and compare it with the value the responsible provider says should be live.
  • Delegation or resolver path is brokenCompare independent resolvers or regional probes together with TTL. Different answers are evidence of cache/authority differences, not a reason to claim a fixed global propagation time.
  • A subdomain used by the page or extension is wrongVerify a subdomain used by the page or extension is wrong from the public Internet and compare it with the value the responsible provider says should be live.
  • Different network DNS settings expose different answersVerify different network DNS settings expose different answers from the public Internet and compare it with the value the responsible provider says should be live.

What to check on your domain

Use the embedded scan to compare the failing layer with adjacent layers that can produce the same visible error. This prevents a DNS change from being used to “fix” a TLS problem, or an SSL-mode change from masking an origin failure.

  • Requested hostname has no usable DNS answerVerify requested hostname has no usable DNS answer from the public Internet and compare it with the value the responsible provider says should be live.
  • Delegation or resolver path is brokenCompare independent resolvers or regional probes together with TTL. Different answers are evidence of cache/authority differences, not a reason to claim a fixed global propagation time.
  • A subdomain used by the page or extension is wrongVerify a subdomain used by the page or extension is wrong from the public Internet and compare it with the value the responsible provider says should be live.
  • Different network DNS settings expose different answersVerify different network DNS settings expose different answers from the public Internet and compare it with the value the responsible provider says should be live.
  • Identify the exact hostname that failedVerify identify the exact hostname that failed from the public Internet and compare it with the value the responsible provider says should be live.

Fixes in the recommended order

Change the smallest confirmed layer first. Preserve working DNS and mail records, document the current value, apply one repair, and then retest before moving to the next possibility.

  • 1. Identify the exact hostname that failed. Confirm the public result after this step before making another unrelated change.
  • 2. Check authoritative and recursive DNS. Confirm the public result after this step before making another unrelated change.
  • 3. Test A and AAAA separately. Confirm the public result after this step before making another unrelated change.
  • 4. If only one client fails, compare its DNS/DoH/network path before editing public DNS. Confirm the public result after this step before making another unrelated change.

How to confirm the repair

HTTPS should complete for the exact hostname, the certificate should be valid for that hostname, and root/www should follow the intended canonical redirect without a TLS error.

If the error remains

Capture the checked hostname, exact timestamp, final DNS addresses, redirect/TLS result and the failing public status before escalating. That evidence gives a hosting or provider support team something testable instead of only the browser message. If results differ by resolver or network, include those differences rather than assuming the failure is universal.

What not to change

Do not replace nameservers, delete unrelated mail records, disable security controls, remove IPv6 blindly or purge the entire configuration merely because this message appears. Diagnose the failing layer first; broad changes can turn one isolated fault into several independent faults.

Technical references

These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.