Active Directory Domain Name with On-Premisis Exchange Server: Split-Brain DNS (split DNS)

Searching the Web produces many articles offering Best Practices for naming the Active Directory Domain on a local LAN.

The prevailing sentiment seems to be to use a subdomain of the entity's primary FQDN.  For example, the company might have an AD domain of or  The LAN AD would use a unique subdomain of the primary FQDN.

My question has to do with Exchange in the above setting.  It seems that the recommended configuration for Exchange is to use  Split-Brain DNS (split DNS).  Unless I am misunderstanding this, that would suggest that I should name the local LAN (rather than or

I would like to better understand the pro's and cons of choosing to configure my AD Domain as a subdomain (e.g., and the impact on deploying an on-premisis Exchange server in that environment.

Please advise.

Thank You.
Who is Participating?
Simon Butler (Sembee)Connect With a Mentor ConsultantCommented:
The name of the Windows domain doesn't really matter, as long as you get the DNS correct.

The main reason people say to use a sub domain, particularly with the increase in web services is that it becomes very clear what is internal and what is external. If you have mobile users then the end user doesn't have to wait for a name resolution attempt to timeout, or a wildcard to get in the way.

However within Exchange, there is one critical part that is affected, and that is Autodiscover.
Externally Autodiscover will want to connect to - where is the part of the email address after the @ sign.
As such, most implementations of Exchange will use something along the lines of for the public facing web services (both internal and external).

The best advice I can give you is to be very clear on the three roles a domain plays:

- The WINDOWS domain.
- The WEB SERVICES domain.
- The EMAIL address.

Having all three the same can work, but does mean particular care has to be taken over the DNS configuration both internally and externally.
Web services and email address domain are often the same, I think almost every deployment I have done which isn't a multi tenant type implementation has been configured like that.

The web services domain is configured within the internal DNS, but it is not the AD DNS zone.

What domain you use for the Windows domain doesn't really matter, as long as it is something that either you control, or does not resolve on the internet.

This last point can be important. With increasing frequency (as AD domains get older) questions are asked about renaming the domain, because it was called, but the company is now called

Perhaps because of a buy out, merger, loss of a legal case etc, or just marketing wanting to eliminate all traces of the old name. Therefore choosing something very generic (ad.local) means that it doesn't matter. I have three sites that I am involved with that use a very generic domain, on purpose. Makes no technical difference, other than ensuring there are no problems later on because of name change.

Don't forget that if you want to use a UCC certificate (e.g. for activesync) then the naming will be important (e.g. .local is no longer supported)
SegulusAuthor Commented:
I though .local was being discouraged due to recent changes changes with SSL Certificates.?
Never miss a deadline with

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

SegulusAuthor Commented:

Are suggesting that I could have an Exchange server name both internal and external to the LAN, and that server can be joined to an AD that is

I though joining the exchange server to the above mentioned domain would automatically make it (rather than  This would give it a different name internal to the LAN as compared to externally.

Am I overlooking something?
yes that's right, but also bear in mind the 5 names you will use - e.g.,, exchange,, etc
SegulusAuthor Commented:
So, if I were to use as my AD Domain would the following be true? - this would be used external to the LAN - would not work from within the LAN but would externally
exchange - I'm not sure what this one is for (just the server name) - for ? - for use inside the LAN

Your help is much appreciated.
biaselectronicsCommented: - this would be used external to the LAN - correct - would not work from within the LAN but would externally - correct, you may want to consider as another name in the UCC
exchange - I'm not sure what this one is for (just the server name) - sometimes inside the domain Outlook can try to connect to the server without a domain - not strictly necessary but useful - for - external access depending on your DNS setup - e.g. you may have clients trying to access - for use inside the LAN - correct
so exchange and are not strictly necessary but you will need to consider your external DNS and exchange settings
You usually get 5 domain names when getting a UCC so in that case I would include the exchange name without a domain...
Simon Butler (Sembee)Connect With a Mentor ConsultantCommented:
First - I would never use the server's real name on the internet.
So if your server is called "Exchange" then the internet name, name on the SL certificate etc would be something like I always use generic names for services, never the server real name.
The main reason is when it comes to updating or replacing the server, or adding an additional one. It makes life very difficult to move services about.

The fact that you cannot have .local on an SSL certificate makes no difference with regards to the name of the domain. As it is just DNS entries it makes no difference.

With regards to the host names above, it looks like you are reading old information.
No longer do you include the server's real NETBIOS or FQDN on the SSL certificate. Two names only need to be included - its alias FQDN ( and Autodiscover (

On Exchange 2013 the clients connect to the FQDN set in Outlook Anywhere. They don't use or even know the name of the real server, because the database does not belong to a server, it is a domain object that is just hosted by the server.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.