Skip to main content
AD Academy
DHCP and Network Preparation
Intermediate16 minLast updated: Topic 4 of 5

DNS in Windows Server: Zones and Records

Forward/Reverse, AD-Integrated, A/AAAA/CNAME/PTR/MX Records, Forwarders and Root Hints.

Not read

What you will learn here

  • Zone Types
  • Record Types You Must Remember
  • Forwarders vs. Root Hints

Worth reading first:Managing DHCP with PowerShell

Analogy: DNS is the phone book of the network. A Forward Lookup Zone answers 'what is the address of this name', and a Reverse Lookup Zone answers the opposite question: 'to whom does this address belong'.

A forward lookup zone maps names to IPs and a reverse lookup zone maps IPs back to names. Both can be AD-integrated, replicating to every domain controller and accepting secure dynamic updates only. Key records: A and AAAA for hosts, CNAME for aliases, PTR for reverse lookups, MX for mail with a priority, SRV to publish domain controller services, NS and SOA for zone authority. External names resolve through a forwarder or directly via root hints.

Zone Types

  • Forward Lookup Zone — translates name ← IP address. This is the primary zone (e.g., lab.local).
  • Reverse Lookup Zone — translates address ← name, based on 10.in-addr.arpa. Important for , printers, and security investigations.
  • AD-Integrated — The zone is stored within and automatically replicated to all DCs. Allows Secure Dynamic Updates only — always recommended in a domain.
  • Primary / Secondary — A regular zone in a file; Secondary is a read-only copy updated via Zone Transfer.
  • Stub Zone — Holds only the NS records of another domain, useful between Forests with Trust.

Record Types You Must Remember

  • A — name ← IPv4 address. AAAA — name ← IPv6 address.
  • CNAME — Alias pointing to another name, for example intranet ← web01.
  • PTR — The reverse record, address ← name, resides in the Reverse Zone.
  • MX — Where mail is sent for the domain, with Priority.
  • SRV — The critical record: it advertises where the Controllers are located (_ldap._tcp.dc._msdcs).
  • NS and SOA — Who are the authoritative servers and who manages the zone.

Forwarders vs. Root Hints

  • Forwarder — 'I don't know, ask this server' (e.g., 8.8.8.8 or the ISP's DNS). Fast and predictable.
  • Root Hints — The server performs the lookup itself against the root servers. A backup when there is no Forwarder.
  • Conditional Forwarder — Only a specific domain is sent to a specific server; a common solution between domains in an organization.
# Create Zones
Add-DnsServerPrimaryZone -Name "lab.local" -ReplicationScope "Forest"
Add-DnsServerPrimaryZone -NetworkId "192.168.10.0/24" -ReplicationScope "Forest"

# Records
Add-DnsServerResourceRecordA -ZoneName "lab.local" -Name "web01" `
  -IPv4Address 192.168.10.20 -CreatePtr
Add-DnsServerResourceRecordCName -ZoneName "lab.local" -Name "intranet" `
  -HostNameAlias "web01.lab.local"
Add-DnsServerResourceRecordMX -ZoneName "lab.local" -Name "." `
  -MailExchange "mail.lab.local" -Preference 10

# Forwarders and Update Security
Set-DnsServerForwarder -IPAddress 8.8.8.8, 1.1.1.1 -UseRootHint $true
Set-DnsServerPrimaryZone -Name "lab.local" -DynamicUpdate Secure

# Tests
nslookup web01.lab.local
nslookup -type=SRV _ldap._tcp.dc._msdcs.lab.local
Resolve-DnsName intranet.lab.local
ipconfig /flushdns; ipconfig /registerdns
powershell
Architecture and theory — Under the hood

AD-Integrated zone is stored within and replicated with replication — no Primary/Secondary, any DC can write, and Secure Dynamic Updates can be enforced.

  • A / AAAA — Name to IPv4 / IPv6 address.
  • PTR — Reverse, found in Reverse Lookup Zone.
  • CNAME — alias for another name.
  • MX — Mail Server. SRV — Service Location (_ldap._tcp.dc._msdcs) — the heart of .
  • Forwarder — sends external queries to a configured server; Root Hints — direct query to root servers.
Practical Configuration (PowerShell / GUI)
Add-DnsServerPrimaryZone -Name "corp.com" -ReplicationScope Domain -DynamicUpdate Secure
Add-DnsServerPrimaryZone -NetworkID "192.168.10.0/24" -ReplicationScope Domain
Add-DnsServerResourceRecordA -ZoneName corp.com -Name srv01 -IPv4Address 192.168.10.20 -CreatePtr
Add-DnsServerForwarder -IPAddress 1.1.1.1
Resolve-DnsName _ldap._tcp.dc._msdcs.corp.com -Type SRV
powershell
Troubleshooting
nslookup -type=srv _ldap._tcp.dc._msdcs.corp.com
ipconfig /flushdns ; ipconfig /registerdns
dcdiag /test:dns /v
bash
  • Old records remain — enable Scavenging (Aging) in the zone.
  • Island DNS — a DC that points only to itself; it is better to point to another DC and then to 127.0.0.1.

Check yourself

What is the main advantage of an AD-Integrated zone?

Which record allows a client to find a Domain Controller?

Was this page helpful?