← Back to knowledge base
Windows ServerFor IT admins

Troubleshoot DNS for Active Directory

Domain joins fail, logons are slow or DCs can't find each other. Most Active Directory problems are DNS problems. Check client settings, DC records and forwarders.

Last verified October 3, 2026

Active Directory finds domain controllers through DNS. If DNS is wrong, sign-ins, Group Policy and replication all fail in confusing ways.

Symptoms

  • Joining a PC to the domain fails with “An Active Directory Domain Controller for the domain could not be contacted”.
  • Slow sign-ins, or Group Policy errors such as event 1129.
  • Replication error 8524, or DNS Server events 4013 and 4004 on a DC.

Cause

  • Clients or servers point to a public DNS server (such as an ISP or 8.8.8.8) instead of your DCs. This is the most common cause.
  • A DC’s own DNS client settings are wrong, so it can’t register its records.
  • Stale records for an old or removed DC.
  • Forwarders that are unreachable, slowing every external lookup.
  • Aggressive scavenging deleting valid records.

Fix

1. Check client DNS settings

On an affected PC:

ipconfig /all

DNS Servers must list only your internal DNS servers (normally your DCs). Fix this in DHCP scope options (option 006), not on each PC.

2. Test that clients can find a DC

nslookup -type=SRV _ldap._tcp.dc._msdcs.yourdomain.local

You should see every DC. Missing DCs mean their records didn’t register.

3. Check the DCs’ own settings

Each DC should use another DC as its preferred DNS server and itself (by its IP, or 127.0.0.1) as an alternate. Never point a DC at a public resolver in its network adapter settings: that’s what forwarders are for.

4. Re-register a DC’s records

On the DC:

ipconfig /registerdns
net stop netlogon && net start netlogon

5. Test DNS health

dcdiag /test:dns /v /e > dcdiag-dns.txt

Review failures for delegation, dynamic update, record registration and forwarders.

If that didn’t work

  • Remove unreachable forwarders in DNS Manager › server › Properties › Forwarders.
  • Review scavenging settings. If both the no-refresh and refresh intervals are under 24 hours, valid records can be deleted.
  • On multi-homed DCs, untick Register this connection’s addresses in DNS on non-domain adapters.
  • Remove stale records for decommissioned DCs, including under _msdcs.

When to call us

  • Event 4013 keeps appearing at DC startup, or a DC was restored from backup.
  • You’re adding or removing a DC, or changing IP addresses on one.

Sources

Didn’t fix it? We can take a look.

Open a ticket