DNS & DHCP

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

What This Category Covers

DNS and DHCP tickets often look like random application failures. Confirm what the client received, what DNS returns, whether leases/reservations conflict, and whether the record is stale or replicated.

First Layer to Isolate

Client lease values first, then resolver answer, scope/interface binding, and record freshness.

Useful Tools, Logs, and Portals

  • ipconfig /all
  • ipconfig /release /renew
  • nslookup against default and explicit DNS server
  • DHCP leases/reservations
  • DNS console/replication

Before You Escalate

  • Client IP/gateway/DNS captured
  • Specific DNS server tested
  • Lease/scope checked
  • Stale/conflicting records reviewed

Articles in This Path

Pick the closest symptom and work from there.

Client receives APIPA address even though DHCP scope has free leasesConditional forwarder works from domain controllers but not DNS management test toolConditional forwarder works on one server onlyDHCP failover pair healthy but one scope stops issuing leasesDHCP lease updates fail after credential account lockoutDHCP option for VoIP phones applies at headquarters but not branch scopeDHCP reservations present but wrong scope hands out addressesDHCP scope has leases available but clients self-assignDNS & DHCP alerts indicate success while end-user experience never changesDNS & DHCP configuration survives testing but resets after restart or syncDNS & DHCP credential or certificate rotation breaks an existing integrationDNS & DHCP feature works in web app but fails in desktop clientDNS & DHCP healthy dashboard status masks a failing production workflowDNS & DHCP logging shows delivery yet the target workflow never completesDNS & DHCP new deployment works for pilot group but not for production rolloutDNS & DHCP policy change applies in admin console but target users never receive itDNS & DHCP quarantine or protection action triggers but recovery workflow failsDNS & DHCP workflow succeeds for one account but fails for shared or delegated accessDNS scavenging removes active record for appliance with static IP reservationDNSSEC validation breaks only one third-party SaaS domain lookupGuest VLAN clients receive lease but no DNS serversInternal DNS record resolves correctly on servers but not on Wi-Fi clientsInternal DNS zone replicates but one domain controller serves stale recordsInternal website resolves to old server for one subnet onlyPrinters renew DHCP but keep old DNS hostnamePTR records missing and backup software fails verificationReserved IP address still handed to wrong MAC after device replacementReverse DNS zone missing PTR updates for new Windows clientsSaaS outage suspected but root cause is local DNS filterStale CNAME causes intranet shortcut to bounce between old and new hosts

Stale CNAME causes intranet shortcut to bounce between old and new hosts

Field Summary

Stale CNAME causes intranet shortcut to bounce between old and new hosts is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Client receives APIPA address even though DHCP scope has free leases

Field Summary

Client receives APIPA address even though DHCP scope has free leases is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

DNSSEC validation breaks only one third-party SaaS domain lookup

Field Summary

DNSSEC validation breaks only one third-party SaaS domain lookup is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. Test by IP and by name so DNS is not confused with raw connectivity.

Reserved IP address still handed to wrong MAC after device replacement

Field Summary

Reserved IP address still handed to wrong MAC after device replacement is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Conditional forwarder works from domain controllers but not DNS management test tool

Field Summary

Conditional forwarder works from domain controllers but not DNS management test tool is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. Test by IP and by name so DNS is not confused with raw connectivity.

DHCP option for VoIP phones applies at headquarters but not branch scope

Field Summary

DHCP option for VoIP phones applies at headquarters but not branch scope is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Internal DNS record resolves correctly on servers but not on Wi-Fi clients

Field Summary

Internal DNS record resolves correctly on servers but not on Wi-Fi clients is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. Test by IP and by name so DNS is not confused with raw connectivity.

Reverse DNS zone missing PTR updates for new Windows clients

Field Summary

Reverse DNS zone missing PTR updates for new Windows clients is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. Test by IP and by name so DNS is not confused with raw connectivity.

DHCP failover pair healthy but one scope stops issuing leases

Field Summary

DHCP failover pair healthy but one scope stops issuing leases is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

DNS scavenging removes active record for appliance with static IP reservation

Field Summary

DNS scavenging removes active record for appliance with static IP reservation is a DNS & DHCP ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. Test by IP and by name so DNS is not confused with raw connectivity.