Visitor

 • 

5 Messages

Thursday, October 2nd, 2025

Unable to access ".mil" websites on home WiFi

I have seen other post regarding this issue, but there are no solutions posted. Websites that end in ".mil" will not load on my home Xfinity WiFi, and the resulting error message reads "DNS_PROBE_FINISHED_NXDOMAIN." This problem is specific to WiFi, as I'm able to access the sites upon turning WiFi off on my phone. Of particular importance is https://milconnect.dmdc.osd.mil, which worked on home WiFi a matter of months ago. I submitted a ticket yesterday, and the response given was "there is no Advanced Security block related to the reported website," but from what I've read on this forum, as well as on other chat platforms, there is an inherent problem with Xfinity WiFi and these sites. Please advise and assist. Thank you.

Oldest First
Selected Oldest First

Accepted Solution

Visitor

 • 

5 Messages

16 days ago

The comma at the end of the link was accidental and only inputted on my post. I've been trying to access this site for several weeks now, and it is still not loading on my home network; it only loads from my phone when I turn WiFi off. I just tired accessing it several more times, and I still get "DNS_PROBE_FINISHED_NXDOMAIN". In fact, I still cannot access any sites that end in ".mil". Thank you for reaching out, and if you can think of anything that's causing, please let me know.

Official Employee

 • 

2.1K Messages

@user_iwq6ty - That's frustrating! The error "DNS_PROBE_FINISHED_NXDOMAIN" strongly suggests a Domain Name System (DNS) issue, and the fact that it only happens on your Xfinity home Wi-Fi and works when you use cellular data points to a problem with your home network's DNS resolution, likely within our gateway or its Advanced Security features.

 

Even if there's no Advanced Security block, the nature of the issue and others' experiences suggest that the default settings or a system-wide block might still be the culprit. Here are the steps to troubleshoot and resolve this, focusing on DNS and potential Xfinity-specific issues:

 

1. Bypass Xfinity DNS
The most common and effective solution is to change the DNS servers your devices or your router uses. Our default DNS servers might be the ones having trouble resolving the .mil domains.

 

Option A: Change DNS on Your Device (Recommended Quick Fix)
Change the DNS settings on your specific device (laptop, desktop, etc.) to use a reliable public DNS service like Google or Cloudflare. This bypasses the DNS set by your Xfinity router for that device only.

- Google Public DNS: Primary: 8.8.8.8, Secondary: 8.8.4.4

- Cloudflare DNS: Primary: 1.1.1.1, Secondary: 1.0.0.1

 

How to change DNS:

1. Search for "Change DNS settings" on your device (Windows, macOS, Android, iOS).

2. Go to your network adapter's properties (Wi-Fi).

3. Manually enter the new DNS server addresses (e.g., Google's 8.8.8.8 and 8.8.4.4).

4. Clear your browser's DNS cache by restarting your browser or, on some operating systems, using a specific command (e.g., ipconfig /flushdns on Windows).

5. Try accessing the .mil site again.

 

Option B: Change DNS on Your Xfinity Gateway (Advanced)
If you have a separate, third-party router connected to the Xfinity modem, you can change the DNS settings on that router so that all connected devices use the new servers. Note: If you are using an Xfinity-provided Wi-Fi gateway (modem/router combo), we often prevent you from changing the DNS settings directly on the device.

 

2. Check and Disable Xfinity Advanced Security
While you were told there's no block, the Xfinity Advanced Security feature (managed via the Xfinity app) has been known to interfere with or block access to certain domains, including government or military sites, due to its security filtering.

1. Open the Xfinity App.

2. Go to the Security section (or similar path depending on your app version).

3. Look for Advanced Security (or xFi Advanced Security).

4. Turn the feature OFF. You may need to confirm the change.

5. Wait 5-10 minutes for the setting to take effect on the gateway.

6. Try accessing the .mil site again.

If this resolves the issue, you can try turning it back on later to see if the problem was a temporary glitch. If the problem returns, you'll need to leave it off or try to find an exclusion setting (though such options are often limited).

 

3. Power Cycle Your Network Equipment
A simple power cycle can clear temporary glitches in the modem's firmware or routing tables.

1. Unplug the power from your Xfinity modem/gateway.

2. Unplug the power from any separate router you may use.

3. Wait 60 seconds.

4. Plug in the Xfinity modem/gateway first. Let it fully boot (lights stop flashing).

5. Plug in your separate router (if applicable).

6. Once the network is fully up, try accessing the .mil site.

 

Final Recommendation
Start with Step 1A (Changing DNS on your device), as it's the easiest and most direct fix for a "DNS_PROBE_FINISHED_NXDOMAIN" error. If that fails, move to Step 2 (Disabling Advanced Security). This combination is what has resolved this specific Xfinity-and-.mil issue for many users. And please let us know if that helps!

(edited)

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Visitor

 • 

5 Messages

Step 1 was the fix. Thank you!

Official Employee

 • 

2.3K Messages

user_iwq6ty Awesome! Happy to hear that did the trick. Our team is always here to ensure you get great support. 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Expert

 • 

114K Messages

18 days ago

FWIW, I'm on the Optimum Online ISP and I get the same message. And the domain name doesn't resolve in a traceroute, and I get a non-existent domain in an NS lookup using the  Cloudflare DNS server. I don't have a solution for you, sorry. Just sayin'. Good luck !

C:\Windows\System32>tracert https://milconnect.dmdc.osd.mil
Unable to resolve target system name https://milconnect.dmdc.osd.mil.

C:\Windows\System32>nslookup https://milconnect.dmdc.osd.mil
Server:  one.one.one.one
Address:  2606:4700:4700::1111

*** one.one.one.one can't find https://milconnect.dmdc.osd.mil: Non-existent domain

Gold Problem Solver

 • 

26.8K Messages

17 days ago

.... Of particular importance is https://milconnect.dmdc.osd.mil, ...

The comma at the end of the link is actually part of the link. When I remove the comma and browse https://milconnect.dmdc.osd.mil the site loads without a problem.

 

Please be aware that there are 2 kinds of responses in this Forum: Replies and Comments. When you Comment on a post by scrolling down to "Comment on this post here...", I am notified of your response. But if you select Reply, I am NOT notified and may not be aware of your response.

Expert

 • 

114K Messages

17 days ago

Hi @BruceW 

For the record, I was not inputting a comma when performing my traceroute and ns lookup. Strangely today, they are working. Maybe something was fixed.

Visitor

 • 

5 Messages

15 days ago

I appreciate everyone's help and insight. A solution exists!

forum icon

New to the Community?

Start Here