AD-DNS-19 - Reverse zone network details should be retrievable
Overviewโ
Detailed information about networks with reverse lookup zones enables:
- Network inventory: Complete list of networks with reverse DNS
- Security auditing: Verification that only authorized networks are configured
- Troubleshooting: Quick identification of reverse DNS coverage
- Documentation: Accurate records of DNS infrastructure
Understanding which networks have reverse zones is essential for comprehensive DNS management.
Security Recommendationโ
Review reverse zone network details regularly:
- Verify all listed networks are authorized
- Ensure CIDR notation is appropriate for each network
- Document the purpose of each reverse zone
- Remove reverse zones for decommissioned networks
How the Test Worksโ
This test provides detailed information about each network with a reverse lookup zone, including:
- Network address
- CIDR notation
- Reverse zone name
- Zone type
Related Testsโ
Test-MtAdDnsReverseZoneCount- Counts reverse lookup zonesTest-MtAdDnsReverseZoneNetworkCount- Counts distinct networks
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DNS-19 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsReverseZoneNetworkDetails |
| Tags | AD, AD-DNS-19, AD.DNS |
Sourceโ
- Pester test:
tests/ad/dns/Test-MtAdDnsReverseZoneNetworkDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsReverseZoneNetworkDetails.ps1

