T The Triage ManualTechnical Guides for IT Emergencies
P1 · Network Infrastructure

DNS server failure

Internal DNS down — authentication fails, applications can't find services, mail flow breaks. AD DNS especially critical.

Indicators

Likely causes

Diagnostic steps

  1. Test resolution from a client: nslookup of an internal A record explicitly against the DNS server
  2. Verify DNS service running on every DC; restart DNS Server service if hung
  3. Test forwarder: nslookup on external name, set server=<forwarder>
  4. Check zone replication: zones must be AD-integrated, replicating with the rest of the directory
  5. Audit conditional forwarders and forwarders for stale targets
  6. Validate scavenging settings — never aggressive on volatile environments

Resolution path

Prevention

Tools

References

dnsactive-directorywindows-serverresolution