mongodb/node-mongodb-native · error · MongoAPIError
Server record does not share hostname with parent URI
Error message
Server record does not share hostname with parent URI
What it means
Thrown by checkParentDomainMatch() when a resolved SRV record address's domain does not end with the srvHost's domain. The driver enforces that every SRV-advertised host be a subdomain of the srvHost from the connection string; a mismatch implies DNS hijacking or misconfiguration. Raised as MongoAPIError.
Solutions
- Correct the DNS SRV records so all targets are subdomains of the srvHost in the connection string.
- Verify with 'dig SRV _mongodb._tcp.<srvHost>' that every returned target ends with the srvHost domain.
- If unintended, investigate possible DNS tampering or a stale/cached record.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoAPIError && /does not share hostname/.test(e.message)) {
// investigate DNS: SRV records must be subdomains of the srvHost
} else throw e;
} Prevention
- Ensure every SRV record target is a subdomain of the srvHost in the connection string.
- Audit DNS records after any infrastructure migration.
- Investigate unexpected records as possible DNS tampering.
When it happens
Trigger: Connecting via mongodb+srv:// where a DNS SRV response returns a hostname that is not under the srvHost domain (e.g. srvHost is cluster.example.com but an SRV record points to evil.attacker.com). This is the core SRV hostname-verification guard.
Common situations: Compromised or misconfigured DNS server returning out-of-domain addresses. Using a custom SRV hostname whose records were edited to point at an unrelated host. Internal DNS changes that forget to update SRV targets.
Related errors
- Server record does not have at least one more domain level…
- Cannot have empty URI params in DNS TXT Record
- Multiple text records not allowed
- No addresses found at host
- Option "srvHost" must not be empty
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/31d50b6106be0643.
Report an issue: GitHub.
Appendix: source
Thrown at src/utils.ts:1186
// will not satisfy an addressDomain that endsWith '.fake-trusted.site'
const addressDomain = `.${normalizedAddress.replace(allCharacterBeforeFirstDot, '')}`;
let srvHostDomain = srvIsLessThanThreeParts
? normalizedSrvHost
: `.${normalizedSrvHost.replace(allCharacterBeforeFirstDot, '')}`;
if (!srvHostDomain.startsWith('.')) {
srvHostDomain = '.' + srvHostDomain;
}
if (
srvIsLessThanThreeParts &&
normalizedAddress.split('.').length <= normalizedSrvHost.split('.').length
) {
throw new MongoAPIError(
'Server record does not have at least one more domain level than parent URI'
);
}
if (!addressDomain.endsWith(srvHostDomain)) {
throw new MongoAPIError('Server record does not share hostname with parent URI');
}
}
/**
* Perform a get request that returns status and body.
* @internal
*/
export function get(
url: URL | string,
options: http.RequestOptions = {}
): Promise<{ body: string; status: number | undefined }> {
return new Promise((resolve, reject) => {
/* eslint-disable prefer-const */
let timeoutId: NodeJS.Timeout;
const request = http
.get(url, options, response => {
response.setEncoding('utf8');
let body = '';View on GitHub (pinned to dce7939f86)