Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x8007007B

Office 0x8007007B: the KMS host name is malformed or does not resolve

10 min read Updated October 5, 2026 Office & Microsoft 365 Licensing

Fix it now

This code has two documented readings and they need different fixes. Microsoft lists it in the Windows activation error codes as “DNS name does not exist”, resolved by troubleshooting DNS; the underlying Win32 error 123 is “the filename, directory name, or volume label syntax is incorrect”. Clear the stored value, set it cleanly, then test resolution.

Run these in an elevated Command Prompt. Use the Program Files (x86) path for 32-bit Office

cd "C:\Program Files\Microsoft Office\root\Office16"
cscript ospp.vbs /remhst
cscript ospp.vbs /sethst:kms.contoso.local
cscript ospp.vbs /act
cscript ospp.vbs /dstatus
  1. Host name only in /sethst:. The port goes in /setprt: as a separate call, and only if the host does not use 1688.
  2. No space after the colon, no protocol prefix, no leading backslashes. slmgr accepts a host and port together; ospp.vbs does not.
  3. If the syntax is clean and it still fails, test the name: nslookup kms.contoso.local, then nslookup -type=all _vlmcs._tcp to see whether the service record exists at all.
  4. /remhst clears the stored host name and resets the port to the default 1688, which is the quickest way back to a known state.

Retype rather than paste. A name copied from a document can carry a non-breaking space or a typographic character that looks identical on screen.

If /dstatus shows the host and port you meant, and /act completes, you are done. If the name is clean and still refused, the next section covers the DNS half.

Why it happens

Two readings of this code are documented and both are real. Microsoft lists 0x8007007B in its Windows activation error codes with the description “DNS name does not exist” and the resolution “troubleshoot DNS-related issues”. Separately, the underlying Win32 error 123, ERROR_INVALID_NAME, is published as “the filename, directory name, or volume label syntax is incorrect”. A string that cannot be parsed and a name that does not exist arrive at the same code from opposite directions.

In practice the split is easy to make. If the code appears the instant you press Enter after /sethst:, you are in the syntax reading. If it appears later, during activation, with a stored name that looks correct, you are in the DNS reading and the fix is in the zone rather than in your typing.

The syntax half has one dominant cause. People arrive at ospp.vbs after years of slmgr, and slmgr /skms accepts a host and port together as one string. Office does not. In ospp.vbs the host name goes to /sethst: and the port goes to /setprt: as a separate call, and Microsoft documents them as two switches taking two values. Putting a colon inside the name field gives the licensing stack something that is not a name.

The two companion Win32 codes describe the same class of complaint from slightly different positions. 0x8007000D is error 13, ERROR_INVALID_DATA, “the data is invalid”, and 0x80070057 is error 87, ERROR_INVALID_PARAMETER, “the parameter is incorrect”. You see them when the string parses far enough to be handed on and still describes nothing usable. 0xC004F018 has no published description at all.

The port was typed into the host name

You have this one if The failure is instant, and the command contains a colon in the middle of the host name.

  1. Clear the stored value: cscript ospp.vbs /remhst.
  2. Set the name alone: cscript ospp.vbs /sethst:kms.contoso.local.
  3. Set the port only if it is not 1688: cscript ospp.vbs /setprt:<port>.
  4. Confirm both landed: cscript ospp.vbs /dstatus.

If the host listens on the default port you can skip /setprt entirely, and /remhst resets the port to 1688 for you.

The string was pasted from a document or a chat client

You have this one if The command looks correct on screen, fails anyway, and retyping it by hand works.

  1. Retype the command rather than pasting it.
  2. If you must paste, paste into a plain text editor first to strip formatting, then copy from there.
  3. Watch for typographic quotes, non-breaking spaces and hyphens that a word processor has substituted.

The name is clean and does not resolve

You have this one if The value stored correctly, /dstatus shows it, and activation fails with the same code.

  1. Resolve the name directly: nslookup kms.contoso.local. A failure here is a DNS problem, not a typing one.
  2. Check the service record too: nslookup -type=all _vlmcs._tcp, which is Microsoft’s documented form.
  3. If the record is missing, have the host republish it, or create it by hand: service _VLMCS, protocol _TCP, port 1688, pointing at the host’s fully qualified name.
  4. Flush the client resolver with ipconfig /flushdns and retry.

The host is in another DNS domain

You have this one if The host exists and the client’s own domain holds no _vlmcs record for it.

  1. On Windows 8.1 and later, name the domain that holds the records: cscript ospp.vbs /skms-domain:<FQDN>, which Microsoft documents as setting the specific DNS domain in which all KMS SRV records appear.
  2. Clear it again with cscript ospp.vbs /ckms-domain when the client should go back to its own domain.
  3. For more than a handful of clients, have the host publish into the extra domains instead, using DnsDomainPublishList.

A bad value keeps coming back

You have this one if Clearing and re-setting works until the next logon or policy refresh, then the malformed value returns.

  1. Find what writes it: a Group Policy preference, a deployment script or a scheduled task.
  2. Correct it at source, then clear the client value with /remhst and set it again.
  3. Confirm after a policy refresh rather than immediately, since that is when it comes back.

Full reference

Strings that will be rejected

What was typed Why it fails
/sethst:kms.contoso.local:1688 The port belongs in /setprt, not in the host name
/sethst:\\kms.contoso.local Leading backslashes make it a UNC path, not a host name
/sethst:http://kms.contoso.local A protocol prefix is not part of a host name
/sethst: kms.contoso.local A space after the colon leaves the host field empty
A name pasted from a document A typographic character or non-breaking space that looks identical on screen

The switches you actually need

Switch What Microsoft says it does
/sethst:<name> Sets a KMS host name using a user-provided host name
/setprt:<port> Sets a KMS port. The default port number is 1688
/remhst Removes the KMS host name and resets the port to the default 1688
/skms-domain:<FQDN> Windows 8.1 and later: sets the specific DNS domain in which all KMS SRV records appear
/ckms-domain Windows 8.1 and later: clears that setting
/dcmid Displays the KMS client computer ID
/dhistorykms Displays the KMS client activation history
/ddescr:<code> Displays the description for a supplied error code

/remhst does two things, and the second is easy to forget: it resets the port to 1688 as well as clearing the name. If your host listens on a non-standard port, you have to set it again afterwards.

Where the value is stored

Microsoft documents the KMS host name as KeyManagementServiceName and the port as KeyManagementServicePort, both REG_SZ values, and notes that these registry values can also be set using the ospp.vbs script. That is the right way round: the script is the supported interface and the registry is where it writes. Editing the values by hand is not necessary and a mistake there is harder to undo than a mistyped command.

Separating a name problem from a network problem

Test What the result tells you
/sethst: fails instantly A syntax problem. Nothing has been looked up yet
nslookup <name> fails The name does not resolve. This is the DNS reading of the code
nslookup -type=all _vlmcs._tcp returns nothing No service record, or the client is searching a domain that has none
The name resolves and /act still fails Not this article. Test the path with Test-NetConnection on port 1688
Test-NetConnection <host> -Port 1688 returns False A firewall or an access list, not a name

On testing with an IP address

Storing a literal address instead of a name is a reasonable diagnostic and a poor permanent configuration. If an address works where the name does not, you have proved the problem is name resolution, which is the useful part. Once proved, put the name back and fix the record, because an address stored on a client survives every future change to the host and fails silently the day it moves.

The undocumented code in this set

0xC004F018 has no published description on any Microsoft page. It appears alongside the others when a KMS configuration cannot be used, and any confident one-line meaning you find for it is unsourced. Run cscript ospp.vbs /ddescr:0xC004F018 on the machine and work from what Office itself says.

Every code this article covers

Code What it points at Source
0x8007007B Published in the Windows activation error codes as “DNS name does not exist”, resolved by troubleshooting DNS. The underlying Win32 error 123 is ERROR_INVALID_NAME, a syntax problem with the name Microsoft Learn
0x8007000D Win32 error 13, ERROR_INVALID_DATA: the data is invalid Microsoft Learn
0x80070057 Win32 error 87, ERROR_INVALID_PARAMETER: the parameter is incorrect Microsoft Learn
0xC004F018 Seen alongside a KMS configuration that cannot be used. No published description not published by the vendor

Confirm the fix worked

  1. cscript ospp.vbs /dstatus shows the host name and port you intended.
  2. nslookup <host name> resolves it from the client.
  3. cscript ospp.vbs /act completes without an error.
  4. The licence status reports as licensed with a remaining period.
  5. Log off and back on, then re-check /dstatus to confirm nothing is overwriting the value.

Questions people ask about this

Is this a typing error or a DNS error?

Both readings are documented. Microsoft lists the code in its Windows activation error codes as “DNS name does not exist”, while the underlying Win32 error 123 is a name syntax problem. If it fails the instant you press Enter, it is syntax; if it fails later during activation with a name that stored correctly, it is DNS.

Why does slmgr accept a host and port together and ospp.vbs not?

Because they are different tools with different switches. slmgr /skms takes a name and optional port in one value. In ospp.vbs, Microsoft documents /sethst: for the host name and /setprt: for the port as two separate switches, each taking one value.

How do I undo a wrong entry?

cscript ospp.vbs /remhst. It removes the stored host name and resets the port to the default 1688, returning the client to automatic discovery.

Do I need to reboot after setting the host name?

No. The value takes effect immediately, so run the activation command straight afterwards.

Can I use an IP address instead of a name?

You can, and it is a useful test: if an address works where the name does not, the problem is name resolution rather than the network path. For anything permanent, store the name and fix the record.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Office 30174-4: Office setup cannot reach the Microsoft servers at all License Error Office 0xC004C009: the activation server rejected the licence License Error Office 0xC004F003: no Office product is attached to this account License Error Office 0xC004F074: no Key Management Service host could be contacted
โ† Back to Knowledge Base