Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When Selenium’s browser runs in a Docker container on Windows and IIS runs on the Windows host, navigate the browser to http://host.docker.internal:<IIS-port>, using the actual port configured for the IIS site. For example, if the site listens on HTTP port 8080, use http://host.docker.internal:8080. Inside the container, localhost refers to the container—not the Windows host. Docker Desktop documents host.docker.internal as the host address containers can use. Docker Desktop networking

This route applies to Docker Desktop’s host-access setup; WSL, remote Docker engines, and Windows containers can have different networking behavior. The Selenium Grid address your test runner uses is also separate from the URL the browser opens.

Identify the IIS URL before changing Selenium

First establish how the site is actually configured on the Windows host. Do not assume IIS uses port 80 or 443: sites can use other ports, and IIS bindings can include a hostname that determines which site responds.

  1. On the Windows host, verify that the intended IIS site loads in a host browser using its configured protocol, port, and hostname.
  2. Check the site’s IIS bindings and record whether it uses HTTP or HTTPS, the port, and any hostname. Microsoft describes IIS sites as using configured bindings; ports 80 for HTTP and 443 for HTTPS are common examples, not guarantees for a particular site. Microsoft IIS site bindings
  3. Use those values when building the URL for the browser container. For HTTP on port 8080 with no host-name binding, for example, the URL is http://host.docker.internal:8080.

If IIS is configured for HTTPS, use https:// and the bound port. The browser container must also trust a certificate valid for the requested hostname; reaching the host does not by itself make an untrusted or mismatched certificate acceptable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Navigate from the Selenium browser container

In Selenium code, set the browser’s destination to the host alias and IIS port. The alias is for the browser’s connection to the Windows host; it is not the Selenium Grid endpoint.

Python example

For a Selenium Python test against an IIS site using HTTP on port 8080:

from selenium import webdriver

options = webdriver.ChromeOptions()
driver = webdriver.Remote(
    command_executor="http://localhost:4444",
    options=options,
)

try:
    driver.get("http://host.docker.internal:8080")
    print(driver.title)
finally:
    driver.quit()

This example assumes the test runner can reach a Selenium Grid published on the same host at port 4444, and that the browser session runs in a Docker Desktop container. Change the Grid URL to match your runner’s actual route. Change the page URL’s protocol, port, and hostname to match the IIS binding. Selenium’s remote-driver configuration separates the Grid connection from navigation; the browser makes the page request from its own network context. Selenium Remote WebDriver

JavaScript example

For a Node.js test using Selenium WebDriver:

const { Builder } = require('selenium-webdriver');

(async function testIis() {
  const driver = await new Builder()
    .usingServer('http://localhost:4444')
    .forBrowser('chrome')
    .build();

  try {
    await driver.get('http://host.docker.internal:8080');
    console.log(await driver.getTitle());
  } finally {
    await driver.quit();
  }
})();

As with Python, localhost:4444 is only an example Grid endpoint for a runner on the host with that port published. It is not the IIS address. If the test runner itself runs in a container, its own localhost refers to that runner container; configure a Grid hostname reachable from it. The browser still needs an address that reaches IIS from the browser container.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle IIS hostname bindings

A request to http://host.docker.internal:8080 can reach the Windows host but select the wrong IIS site—or no site—if the intended site is bound to a particular hostname. IIS uses host-name bindings to distinguish sites sharing an address and port. Check the binding in IIS and ensure the request carries the expected host name. Microsoft IIS site bindings

If the site requires a hostname such as app.local.test, use a hostname-based URL and configure name resolution so the browser container can reach the host under that name. Do not assume that merely changing the URL’s hostname will resolve it inside the container. For HTTP, the hostname in the URL also determines the HTTP Host header used for IIS site selection. For HTTPS, the hostname additionally affects certificate name validation and TLS server-name indication. The exact DNS or hosts-file setup depends on your container and Docker backend; use a hostname resolution route available to that browser environment, and verify the resulting request against the IIS binding.

Choose the right address for your Docker environment

host.docker.internal is specifically documented by Docker Desktop for containers reaching host services. It should not be treated as a universal hostname for every Docker Engine installation or network topology. Docker Desktop networking

Runtime arrangement Starting address for IIS on Windows Qualification
Docker Desktop browser container on Windows host.docker.internal:<IIS-port> Confirm the IIS binding and host firewall allow the connection. Docker Desktop
Linux container using WSL NAT networking Windows host IP plus the IIS port Microsoft’s WSL guidance describes using the host IP for Linux-to-Windows access in default NAT mode. Microsoft WSL networking
WSL mirrored networking localhost may be reachable This depends on supported Windows 11 and WSL configurations; it does not establish that localhost works in every Docker setup. Microsoft WSL networking
Windows container Determine the route for the selected Windows network mode Windows container networking has modes including NAT, transparent, overlay, and l2bridge; Microsoft lists host networking as unsupported for Windows containers. Microsoft Windows container networking

Linux containers running on Windows use virtualization rather than running directly on the Windows kernel, so their network route should not be inferred from Windows-container networking. Microsoft Windows containers overview If Docker is running through a remote daemon or a CI service, the relevant “host” may be the machine running that daemon—not your development PC. Confirm which machine owns IIS before selecting an address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot connection failures in network order

Test from the browser container’s network context. A successful page load in a Windows host browser only proves that IIS is reachable from Windows; it does not prove the container has the same DNS, route, firewall access, or certificate trust.

  1. Verify the runtime. Confirm whether the browser is in Docker Desktop, WSL-backed Docker, a remote engine, a Linux container, or a Windows container. Use the address strategy for that actual arrangement.
  2. Verify IIS locally. On Windows, load the exact scheme, port, and hostname from the site binding. If that fails on the host, fix IIS configuration before debugging Docker.
  3. Verify the requested port and protocol. A site on port 8080 is not reached by omitting the port and defaulting to 80. Use http for an HTTP binding and https only for an HTTPS binding.
  4. Check name resolution and routing. From a shell in the browser container, if one is available, check whether host.docker.internal resolves and whether the target port is reachable. A name-resolution failure points to the runtime or DNS setup; a resolved name with a failed connection points toward routing, listening-interface, firewall, or port configuration.
  5. Check IIS site selection. If a response arrives but it is the wrong site, compare the request hostname with IIS’s configured host-name binding. Make the browser request use the hostname IIS expects and ensure it resolves from the container.
  6. Check HTTPS trust. If HTTP works but HTTPS fails, inspect whether the certificate is trusted in the browser container and whether its subject name matches the hostname in the URL. Prefer configuring an appropriate trusted certificate for test environments rather than disabling certificate checks.
  7. Separate Grid errors from page errors. If Selenium cannot create a session, inspect the runner-to-Grid URL, Grid availability, and published port. If the session starts but navigation fails, investigate the browser-container-to-IIS route instead. These are separate connections. Selenium Remote WebDriver

Or skip the browser setup

If your goal is to capture a website rather than test it through Selenium, ScreenshotNeo can return a screenshot or PDF with one GET request. Its API also accepts options for formats such as PNG, JPEG, and WebP; consult the ScreenshotNeo API documentation for request parameters.

curl -G "https://api.screenshotneo.com/v1/shot" 
  -d access_key=YOUR_API_KEY 
  --data-urlencode url=https://stripe.com 
  -o shot.webp

ScreenshotNeo accepts cookie or consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each of those steps can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. ScreenshotNeo is a screenshot API and MCP server made by Yorker Media.

Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently asked questions

Does changing localhost to host.docker.internal change the Selenium Grid URL?

No. It changes the browser’s destination when it navigates to the application. Keep the Grid endpoint configured separately for the test runner’s connection to Selenium.

Can this approach test an IIS site that is only available on a private network?

Only if the browser container has a network route and permission to reach that host. The Docker Desktop host alias addresses a service on the Docker host; it does not automatically provide access to a different private-network server.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.