Skip to main content
AD Academy
From Zero: Network, Server and Domain
Beginner14 minLast updated: Topic 2 of 4

DNS — the heart of Active Directory

A, PTR, SRV records and why there's no Domain without DNS.

Not read

What you will learn here

  • Why there is no domain without DNS
  • A vs PTR vs SRV records
  • How a computer finds a DC

Worth reading first:Networking from zero: IP, Subnet, Gateway

DNS is the phone book of the network. doesn't just use DNS — it depends on it completely: the client finds the through SRV records.

Record types worth knowing

  • A — name → IPv4 address (dc01.lab.local → 192.168.10.10).
  • PTR — IP address → name (Reverse Lookup).
  • CNAME — an alias for another name.
  • SRV — advertises services: '_ldap._tcp.dc._msdcs.lab.local' points to the DC.
# Are the DC's SRV records present?
Resolve-DnsName -Type SRV _ldap._tcp.dc._msdcs.lab.local

# Re-register DC records (run on the DC)
nltest /dsregdns

# Clear DNS cache on client
Clear-DnsClientCache
powershell
Architecture and Theory — Under the Hood

lives and breathes on DNS. Every client finds a DC by querying SRV records: _ldap._tcp.dc._msdcs.<domain>. Without correct DNS — no login, no , no replication. Therefore, the first DC is always also a DNS server.

  • SRV records discover services: _kerberos._tcp, _ldap._tcp, _gc._tcp.
  • A records for DC + CNAME record with its GUID — critical for replication.
  • The _msdcs.<forest> zone is replicated to the entire forest — allowing every domain to find foreign DCs.
  • Windows registers itself in DNS via DDNS (Dynamic Update).
Practical Configuration (PowerShell / GUI)
# SRV record check
nslookup -type=SRV _ldap._tcp.dc._msdcs.corp.local
Resolve-DnsName _ldap._tcp.dc._msdcs.corp.local -Type SRV

# Force re-registration of DC in DNS
ipconfig /registerdns
nltest /dsregdns

# Check that the client finds DC
nltest /dsgetdc:corp.local
powershell
Real-world Scenarios in an Organization
  • A computer cannot join the domain — the problem is almost always incorrect DNS on the network card.
  • is not applying → dcdiag /test:dns + SRV check.
  • Replication between DCs fails → problem with _msdcs.forestname.
Troubleshooting
dcdiag /test:dns /v
ipconfig /flushdns
ipconfig /registerdns
nslookup -type=any _ldap._tcp.corp.local
bash
Glossary and Quick Command Line
  • Primary DNS = DC. Secondary DNS = another DC. 8.8.8.8 is forbidden on workstations.
  • SRV = Service Locator. A = Address Locator.
  • _msdcs = The critical zone.

Check yourself

Which DNS record lets a client locate a Domain Controller?

Was this page helpful?