AD-DNS-17 - Non-standard zone count should be retrievable
Overviewβ
Non-standard DNS zone names (not compliant with RFCs 952, 1035, and 1123) may cause:
- Compatibility issues: Some DNS clients and applications may fail
- Resolution problems: Non-standard names may not resolve correctly
- Management difficulties: Unusual characters can complicate administration
- Security risks: Special characters might be used in injection attacks
Standard DNS names should contain only letters, numbers, and hyphens.
Security Recommendationβ
- Use only RFC-compliant names for DNS zones
- Rename or remove zones with non-standard names
- Implement naming conventions that follow RFC standards
- Audit zone names regularly for compliance
How the Test Worksβ
This test identifies zones with names that do not comply with RFC standards for internet domain names, excluding special zones like TrustAnchors and _msdcs.
Related Testsβ
- None currently
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-17 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsNonStandardZoneCount |
| Tags | AD, AD-DNS-17, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsNonStandardZoneCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsNonStandardZoneCount.ps1

