Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Windows Dns

ASecurity

Expert coverage of Windows DNS Server across all versions: AD-integrated zones, replication scopes, DNS policies, zone scopes, DNSSEC, aging/scavenging, and PowerShell DNS management. Use for \"Windows DNS\", \"AD-integrated zones\", \"DNS policy\", \"zone scope\", \"DnsServer PowerShell\", \"dnscmd\", \"scavenging\", \"DNS Server role\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill.

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopsrustgoshellazuresecurity

Works with

cli

Security Analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill windows-dns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Windows Dns?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Windows Dns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-windows-dns/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-windows-dns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: windows-dns
description: "Expert coverage of Windows DNS Server across all versions: AD-integrated zones, replication scopes, DNS policies, zone scopes, DNSSEC, aging/scavenging, and PowerShell DNS management. Use for \"Windows DNS\", \"AD-integrated zones\", \"DNS policy\", \"zone scope\", \"DnsServer PowerShell\", \"dnscmd\", \"scavenging\", \"DNS Server role\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill."
license: MIT
---

# Windows DNS Server

This skill covers Windows DNS Server across all supported versions (Server 2016, 2019, 2022, 2025). Areas of expertise include:

- AD-integrated zones with replication scopes (ForestDnsZones, DomainDnsZones)
- Zone types: primary, secondary, stub, conditional forwarder, reverse lookup
- DNS Policies and Zone Scopes for split-brain and geo-routing
- DNSSEC signing, key management, trust anchors
- Aging and scavenging for stale record cleanup
- DnsServer PowerShell module for full automation
- Secure dynamic updates in AD environments

## How to Approach Tasks

1. **Classify** the request:
   - **Zone management** -- Zone creation, replication scope, zone transfers
   - **Record management** -- Add/modify/delete DNS records via PowerShell or GUI
   - **DNS Policies** -- Split-brain, geo-routing, DNS sinkholing (PowerShell only)
   - **DNSSEC** -- Zone signing, key management, trust anchors
   - **Troubleshooting** -- Event IDs, debug logging, resolution failures
   - **Scavenging** -- Aging/scavenging configuration, stale record cleanup

2. **Identify version** -- Server 2016 introduced DNS Policies. Server 2022 added client DoH. Server 2025 adds server-side DoH (preview).

3. **Identify AD integration** -- Is DNS running on a Domain Controller? AD-integrated vs file-based zones have different replication and security models.

4. **Recommend** -- Provide PowerShell examples (preferred over dnscmd for new deployments).

## Core Architecture

### AD-Integrated Zones

When DNS runs on a Domain Controller, zones stored in AD provide:
- Multi-master updates (any DC can accept dynamic updates)
- Automatic replication via AD replication topology
- Secure-only dynamic updates (only authenticated domain computers register)
- Encrypted storage as AD DS objects

### Replication Scopes

| Partition | Scope | Use Case |
|---|---|---|
| `ForestDnsZones` | All DCs in forest running DNS | Cross-domain zones, `_msdcs` |
| `DomainDnsZones` | All DCs in domain running DNS | Default for domain zones |
| Domain partition | All DCs in domain | Legacy Windows 2000 compat |
| Custom partition | Admin-defined subset | Selective replication |

### Zone Types

- **Primary**: Read/write authoritative copy (file-based or AD-integrated)
- **Secondary**: Read-only copy via AXFR/IXFR (file-based only)
- **Stub**: SOA + NS + glue records only (delegation discovery)
- **Conditional Forwarder**: Forwards specific domain queries to designated servers
- **Reverse Lookup**: PTR records for IP-to-name resolution

### DNS Policies (Server 2016+)

DNS Policies allow behavior customization based on client subnet, query type, FQDN, time of day, transport protocol. **PowerShell only -- no GUI.**

Key objects: Client Subnets, Zone Scopes, Recursion Scopes, Query Resolution Policies, Zone Transfer Policies.

Use cases: geo-location routing, split-brain DNS, DNS sinkholing, recursion control.

### DNSSEC

Windows supports DNSSEC on primary zones (file-backed and AD-integrated):
- Key Master: authoritative server generating/distributing signing keys
- KSK rollover: double-signature method; DS record at parent updated manually
- ZSK rollover: prepublish method; fully automatic
- Recommended algorithm: ECDSAP256/SHA-256 with NSEC3

### Aging and Scavenging

Removes stale dynamically-registered records:
- **No-refresh interval** (default 7 days): suppress refresh writes to AD
- **Refresh interval** (default 7 days): window for record refresh
- Total record lifetime before scavenging = no-refresh + refresh = 14 days
- Must be enabled at BOTH server level AND zone level
- Only dynamic records (non-zero timestamp) are eligible

```powershell
Set-DnsServerScavenging -ScavengingState $True -ScavengingInterval 7.00:00:00
Set-DnsServerZoneAging -ZoneName "contoso.com" -Aging $True
```

## Key PowerShell Cmdlets

```powershell
# Zone management
Add-DnsServerPrimaryZone -Name "example.com" -ReplicationScope "Forest"
Add-DnsServerSecondaryZone -Name "partner.com" -ZoneFile "partner.com.dns" -MasterServers 10.1.1.53
Add-DnsServerConditionalForwarderZone -Name "cloud.com" -MasterServers "10.1.1.53" -ReplicationScope "Domain"

# Records
Add-DnsServerResourceRecord -ZoneName "example.com" -A -Name "www" -IPv4Address "10.0.0.10"
Get-DnsServerResourceRecord -ZoneName "example.com" -RRType "A"

# Forwarders
Set-DnsServerForwarder -IPAddress "8.8.8.8","8.8.4.4" -UseRootHint $True

# DNSSEC
Invoke-DnsServerZoneSign -ZoneName "example.com" -SignWithDefault -Force
Get-DnsServerDnsSecZoneSetting -ZoneName "example.com"

# Policies
Add-DnsServerClientSubnet -Name "InternalSubnet" -IPv4Subnet "10.0.0.0/8"
Add-DnsServerZoneScope -ZoneName "example.com" -Name "InternalScope"
Add-DnsServerQueryResolutionPolicy -Name "InternalPolicy" -Action ALLOW -ClientSubnet "eq,InternalSubnet" -ZoneScope "InternalScope,1" -ZoneName "example.com"

# Diagnostics
Get-DnsServerStatistics
Set-DnsServerDiagnostics -Queries $True -Answers $True
```

## Troubleshooting Event IDs

| Event ID | Description |
|---|---|
| 4000 | Cannot open Active Directory -- zone data unavailable |
| 4007 | Cannot find AD -- disabling AD zones |
| 4013 | Waiting for AD DS initialization |
| 4015 | Critical error from Active Directory |
| 1014 (client) | Name resolution timed out |

## Common Pitfalls

1. **Scavenging not enabled at both levels** -- Scavenging requires enablement at server level AND zone level. Missing either means no cleanup.
2. **Scavenging too aggressive** -- Setting scavenging interval shorter than DHCP lease duration deletes records for active clients. Rule: scavenging period = DHCP lease + 1 day.
3. **Static records aged out** -- Manually created records have timestamp 0 (exempt). But `dnscmd /ageallrecords` makes ALL records eligible -- use with caution.
4. **DNS Policies invisible in GUI** -- DNS Policies are PowerShell-only. Admins using only DNS Manager will not see configured policies.
5. **Conditional forwarder not AD-replicated** -- If not using `-ReplicationScope`, conditional forwarders must be configured on each DNS server manually.
6. **DNSSEC DS record not updated at parent** -- After KSK rollover, the DS record at the parent zone must be updated manually. Failure causes validation failures.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 2022 | `references/versions/2022.md` | Client-side DoH, DNSSEC improvements, Azure Arc integration |
| 2025 | `references/versions/2025.md` | Server-side DoH (preview), continued DNS Policy support |

## Reference Files

- `references/architecture.md` -- AD-integrated zones, replication, DNS policies, zone scopes, DNSSEC key management
- `references/best-practices.md` -- Aging/scavenging, forwarder design, split-brain, PowerShell management, secure dynamic updates

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

971540 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →