Skip to content

Internal servers should be reachable via an internal name, the same domain must resolve differently externally

Split-horizon (split-brain) DNS returns different answers depending on the source of the query. Classic for on-prem servers on private IPs that should only be reachable externally via VPN.

Try this first

  1. 1First decide whether split-horizon is truly needed. For fully cloud setups a single public DNS zone is usually simpler and safer.
  2. 2Keep zone names identical (vectel.nl internal and external) but let an internal resolver (Active Directory DNS, Pi-hole, Unbound) override specific records.
  3. 3Avoid different values for public records (MX, SPF, TXT). Keep them identical, otherwise mail and API tests from inside break.
  4. 4Document which records differ internally, because anyone troubleshooting without that knowledge gets lost.
  5. 5Test from both inside and outside regularly with dig or nslookup, a single DHCP change that bypasses the internal resolver wrecks it.

When to bring us in

If you have a hybrid setup where internal and external diverge and mail delivery acts up, we can redesign the DNS architecture.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.