Client resolves domain but not kerberos records for site

Minimal guidance for messy support realities.

Scenario

Basic domain lookup works, but Kerberos or LDAP site-specific record lookups fail.

Recommended Resolution Path

  1. Inspect the site-specific SRV records in the AD-integrated zone.
  2. Check whether the client is truly mapped to the expected site and subnet.
  3. Compare DNS responses from each domain DNS server if replication is suspect.
  4. Fix the site records rather than teaching clients alternate domain controller paths.

Technician Notes

Capture the exact scope of impact, confirm which dependency failed first, and document whether the issue reflects broader domain or server drift.