Skip to main content
Version: 2.2.1-preview

AD-DNS-17 - Non-standard zone count should be retrievable

Overview​

Non-standard DNS zone names (not compliant with RFCs 952, 1035, and 1123) may cause:

  • Compatibility issues: Some DNS clients and applications may fail
  • Resolution problems: Non-standard names may not resolve correctly
  • Management difficulties: Unusual characters can complicate administration
  • Security risks: Special characters might be used in injection attacks

Standard DNS names should contain only letters, numbers, and hyphens.

Security Recommendation​

  • Use only RFC-compliant names for DNS zones
  • Rename or remove zones with non-standard names
  • Implement naming conventions that follow RFC standards
  • Audit zone names regularly for compliance

How the Test Works​

This test identifies zones with names that do not comply with RFC standards for internet domain names, excluding special zones like TrustAnchors and _msdcs.

  • None currently

Test Metadata​

FieldValue
Test IDAD-DNS-17
SeverityInfo
SuiteActive Directory
CategoryAD.DNS
PowerShell testTest-MtAdDnsNonStandardZoneCount
TagsAD, AD-DNS-17, AD.DNS

Source​

  • Pester test: tests/ad/dns/Test-MtAdDnsNonStandardZoneCount.Tests.ps1
  • PowerShell source: powershell/public/ad/dns/Test-MtAdDnsNonStandardZoneCount.ps1