A browser message saying a site cannot be reached may be caused by DNS, but it can also be a proxy, certificate, firewall or site outage. `nslookup` asks a DNS server directly and reports the server used, so it helps distinguish name resolution from a general connection problem. A single successful lookup is not proof that the browser path works; it is one branch of the investigation.
Before you start
Choose a legitimate domain you know should resolve and record the original failing domain. Note your configured DNS server and whether a VPN, work profile or DNS-over-HTTPS browser setting is active. Avoid switching to a public DNS server on a managed device without approval because internal names and filtering may depend on corporate DNS.Do it step by step
- Confirm the adapter has an address and default gateway with `ipconfig /all`. If it has a 169.254.x.x address or no gateway, fix network assignment first; DNS is downstream.
- Run `nslookup example.com` and then the failing legitimate domain. Record the Server line, returned addresses or error and timestamp. A result for one name but not the other suggests a domain-specific or policy problem.
- Compare the same lookup from a second device on the same network and, if safe, from the PC on a phone hotspot. If the failure follows the router, inspect its DNS configuration or provider rather than changing Windows files.
- If the configured resolver is failing only on this PC, run `ipconfig /flushdns` once and retry. Microsoft's ipconfig documentation confirms this clears the local resolver cache; it does not repair an unreachable external DNS server.
- Inspect VPN and proxy state and the browser's own secure-DNS setting. Browser DNS-over-HTTPS may produce a different result from a plain nslookup query; note that distinction rather than calling either result wrong.
- Restore any temporary test settings, then verify the target site in the actual browser or app. Document whether the fix was local cache, resolver configuration, VPN or a remote outage.