dial tcp: lookup registry-1.docker.io on CONTAINER_IP:53: no such host
Fixes docker pull/build failing with DNS 'no such host' for the registry. Use when the daemon cannot resolve registry hostnames, pointing at host or daemon DNS misconfiguration. Not for auth failures or rate limits.
TL;DR: The daemon's DNS cannot resolve the registry. Check the host resolves it (nslookup registry-1.docker.io); if the host is fine but docker is not, set explicit DNS servers for the daemon in /etc/docker/daemon.json ({"dns": ["8.8.8.8", "1.1.1.1"]}) and restart docker. VPNs and corporate resolvers that do not answer from inside docker's network namespace are the usual cause.
The error
dial tcp: lookup registry-1.docker.io on CONTAINER_IP:53: no such hostFix it
Test host DNS:
nslookup registry-1.docker.ioExpected: if this fails too, fix the host network first (cable, VPN, /etc/resolv.conf).If the host resolves fine, give the daemon explicit DNS: add to /etc/docker/daemon.json:
{"dns": ["8.8.8.8", "1.1.1.1"]}Restart and retry:
sudo systemctl restart docker && docker pull hello-worldExpected: pull works.
When this applies
- Pulls and builds fail on name resolution while the browser/host works
- Laptops moving between corporate VPN and home networks
When this does NOT apply
- "no such host" for YOUR private registry (that hostname may genuinely not exist; check spelling and internal DNS)
- Timeouts rather than NXDOMAIN (connectivity, not DNS)
Versions
All Docker Engine versions.
Why it happens
Containers and the daemon use the host's /etc/resolv.conf by default. Corporate DNS servers often refuse queries from unexpected subnets, and VPN clients rewrite resolv.conf on connect/disconnect, leaving docker pointing at a dead resolver.
Edge cases
- systemd-resolved stub at 127.0.0.53 breaks docker's embedded DNS in some setups; the explicit
dnsarray bypasses it. --dnsondocker runoverrides per-container without touching the daemon config.- Some registries are region-specific; "no such host" can also mean the mirror hostname in daemon.json is wrong.