Allow DNS suffix appending to unqualified multi-label name queries
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Vista
Path in the GPO console
Computer Configuration\Administrative Templates\Network\DNS Client Description
Specifies that the DNS client may attach suffixes to an unqualified multi-label name before sending subsequent DNS queries if the original name query fails. A name containing dots, but not dot-terminated, is called an unqualified multi-label name, for example "server.corp" is an unqualified multi-label name. The name "server.corp.contoso.com." is an example of a fully qualified name because it contains a terminating dot. For example, if attaching suffixes is allowed, an unqualified multi-label name query for "server.corp" will be queried by the DNS client first. If the query succeeds, the response is returned to the client. If the query fails, the unqualified multi-label name is appended with DNS suffixes. These suffixes can be derived from a combination of the local DNS client's primary domain suffix, a connection-specific domain suffix, and a DNS suffix search list. If attaching suffixes is allowed, and a DNS client with a primary domain suffix of "contoso.com" performs a query for "server.corp" the DNS client will send a query for "server.corp" first, and then a query for "server.corp.contoso.com." second if the first query fails. If you enable this policy setting, suffixes are allowed to be appended to an unqualified multi-label name if the original name query fails. If you disable this policy setting, no suffixes are appended to unqualified multi-label name queries if the original name query fails. If you do not configure this policy setting, the DNS client will use its local settings to determine the query behavior for unqualified multi-label names.
Registry
Software\Policies\Microsoft\Windows NT\DNSClient Value name: AppendToMultiLabelName
Enabled: AppendToMultiLabelName = 1
Disabled: AppendToMultiLabelName = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_DnsClient/DNS_AppendToMultiLabelName Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Allow DNS suffix appending to unqualified multi-label name queries
; State: Enabled
; Supported on: At least Windows Vista
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient]
"AppendToMultiLabelName"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppendToMultiLabelName' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_DnsClient/DNS_AppendToMultiLabelName
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient' -Name 'AppendToMultiLabelName' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppendToMultiLabelName' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient' -Name 'AppendToMultiLabelName' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow DNS suffix appending to unqualified multi-label name queries
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\DNSClient'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppendToMultiLabelName' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.