{"record":{"id":"c32caa5592db0cad","repo":"mongodb/node-mongodb-native","slug":"server-record-does-not-have-at-least-one-more-doma","errorCode":null,"errorMessage":"Server record does not have at least one more domain level than parent URI","messagePattern":"Server record does not have at least one more domain level than parent URI","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/utils.ts","lineNumber":1181,"sourceCode":"  const allCharacterBeforeFirstDot = /^.*?\\./;\n  const srvIsLessThanThreeParts = normalizedSrvHost.split('.').length < 3;\n  // Remove all characters before first dot\n  // Add leading dot back to string so\n  //   an srvHostDomain = '.trusted.site'\n  //   will not satisfy an addressDomain that endsWith '.fake-trusted.site'\n  const addressDomain = `.${normalizedAddress.replace(allCharacterBeforeFirstDot, '')}`;\n  let srvHostDomain = srvIsLessThanThreeParts\n    ? normalizedSrvHost\n    : `.${normalizedSrvHost.replace(allCharacterBeforeFirstDot, '')}`;\n\n  if (!srvHostDomain.startsWith('.')) {\n    srvHostDomain = '.' + srvHostDomain;\n  }\n  if (\n    srvIsLessThanThreeParts &&\n    normalizedAddress.split('.').length <= normalizedSrvHost.split('.').length\n  ) {\n    throw new MongoAPIError(\n      'Server record does not have at least one more domain level than parent URI'\n    );\n  }\n  if (!addressDomain.endsWith(srvHostDomain)) {\n    throw new MongoAPIError('Server record does not share hostname with parent URI');\n  }\n}\n\n/**\n * Perform a get request that returns status and body.\n * @internal\n */\nexport function get(\n  url: URL | string,\n  options: http.RequestOptions = {}\n): Promise<{ body: string; status: number | undefined }> {\n  return new Promise((resolve, reject) => {\n    /* eslint-disable prefer-const */","sourceCodeStart":1163,"sourceCodeEnd":1199,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/utils.ts#L1163-L1199","documentation":"Thrown by checkParentDomainMatch() when the SRV hostname has fewer than three dot-separated parts and a returned SRV record address does not contain at least one more domain level than the parent srvHost. This is a security guard: SRV records for short hosts (e.g. 'cluster.mongodb.net') must advertise addresses with strictly deeper domains to prevent DNS hijacking via sibling/subdomain tricks. Raised as MongoAPIError.","triggerScenarios":"Connecting via a mongodb+srv:// connection string where the DNS SRV response advertises an address whose domain depth is not greater than the srvHost when the srvHost has fewer than three parts. Typically a DNS misconfiguration or, in worst case, a compromised DNS server.","commonSituations":"Custom or private DNS deployments with short srvHost names (fewer than three labels). Misconfigured SRV records in internal service discovery. Rare on standard Atlas-style hostnames which have >= 3 parts.","solutions":["Ensure SRV records advertise addresses that are subdomains of (deeper than) the srvHost.","Use a fully-qualified srvHost with at least three domain parts (e.g. cluster.example.com).","Verify DNS configuration with 'dig SRV _mongodb._tcp.your.srv.host' and fix malformed records."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoAPIError && /at least one more domain level/.test(e.message)) {\n    // fix SRV records to advertise deeper subdomains; use a >=3-part srvHost\n  } else throw e;\n}","preventionTips":["Use a fully-qualified srvHost with at least three domain parts (e.g. cluster.example.com).","Verify SRV records with 'dig SRV _mongodb._tcp.<srvHost>' before deploying.","Ensure all SRV-advertised hosts are proper subdomains of the srvHost."],"tags":["dns","srv","security","connection-string"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}