``So what if my host leaks a few packets to the global Internet? '' The reason is that inconsistent configuration between your home hosts and your local DNS servers can, and often does, cause leakage of DNS updates for private IP addresses to the global Internet.

the machines and devices you want to register into DNS are not in an Active Directory.

Therefore, that means none of your Windows computers have been configured with a Primary DNS Suffix.

When you join a computer to a domain, one of the many things that occur on the computer is that the Primary DNS Suffix is automatically configured, which matches the name of the AD DNS domain name, which should also be identical to the DNS zone name.

And further, as we already know, that’s what a computer needs to register into a zone with the same name.

Both DHCP clients and servers can generate DNS updates.

To turn off DNS updates on Windows 2000/XP/2003 configured with DHCP clients (refer to Figure 1): To turn off DNS updates on Window Server 2000 running DHCP Server (refer to Figure 2 below): Microsoft Windows Server 2003™ automatically sends DNS updates to each of its DHCP clients.

The following list illustrates a typical example of how a private DNS update leaks out to the global Internet. The DHCP client first sends a query to its local domain name server (LDNS) and asks for the authoritative server for the zone of its domain name (step 3).

Once the DHCP client receives a response (step 4), it sends the update to the indicated server (step 5).

Similarly, steps 6-8 update the inverse mapping from the IP address to the domain name (type PTR RR).

