{"version":"2.1.284","anchor":"sandbox-denieddomains-matches-the-canonicalised-host","canonical_anchor":"sandbox-denieddomains-matches-the-canonicalised-host","heading":"Sandbox blocked-website rules now catch other spellings of the same host","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-denieddomains-matches-the-canonicalised-host","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox blocked-website rules now catch other spellings of the same host\n\n`deniedDomains` rules now also match a host written another way, such as a different IP address spelling or a trailing dot\n\n**Unclear.** Exactly which alternative spellings are recognised is not fully settled.\n\n**What**\n\nBlock rules in `sandbox.network.deniedDomains` are now checked against a standard form of the host as well as the host exactly as written. The standard form smooths out different ways of writing an IP address and a trailing dot. When a connection is blocked, the reason names both forms.\n\nThe sandbox's network relay (the SOCKS proxy that carries sandboxed network traffic) now answers \"connection not allowed\" when a rule blocks a connection, instead of \"host unreachable\".\n\n**Why**\n\nA blocked host can no longer be reached just by writing its address differently, and a blocked connection is now reported as blocked rather than as a host that could not be found.\n\n- Area: Sandbox\n- Names: `sandbox.network.deniedDomains`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}