AD-DNS-16 - Reverse lookup zone count should be retrievable
Overviewβ
Reverse lookup zones enable IP-to-name resolution (PTR records) and are essential for:
- Security auditing: Identifying systems by IP address
- Network troubleshooting: Resolving IPs to hostnames
- Application functionality: Many services require reverse DNS
- Compliance: Some regulations require reverse DNS configuration
The number of reverse zones indicates network coverage for reverse resolution.
Security Recommendationβ
- Maintain reverse zones for all internal networks
- Ensure reverse records are kept synchronized with forward records
- Protect reverse zones from unauthorized modification
- Monitor for unexpected changes to reverse zones
How the Test Worksβ
This test counts reverse lookup zones (zones ending in .in-addr.arpa for IPv4 and .ip6.arpa for IPv6).
Related Testsβ
Test-MtAdDnsReverseZoneNetworkCount- Counts distinct networks with reverse zonesTest-MtAdDnsReverseZoneNetworkDetails- Provides detailed network information
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-16 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsReverseZoneCount |
| Tags | AD, AD-DNS-16, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsReverseZoneCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsReverseZoneCount.ps1

