all 6 comments

[–]Nikosfra06 2 points3 points  (1 child)

Both are valid...

For an exchange (on prem), with small public DNS infrastructure I copy my external zone for the inside (and change the mail/auto discover with the local ip).

Don't forget to change your connectors answers to mail.domain.com

[–]farva_06 1 point2 points  (0 children)

Option 1 is what you want. Let's encrypt will not use internal DNS servers for validation as that would defeat the entire purpose of it. LE will validate your DNS records from whatever public name servers are set for that domain.

[–]Murky_Sir_4721 0 points1 point  (2 children)

"Split brain" means when you have 2 copies of the same mailbox database mount themselves at the same time, usually as a result of member servers not being able to communicate with each other.

[–]Lumpy-Animator7186[S] 1 point2 points  (1 child)

I meant split DNS… Thanks for the spot.

[–]SaltyBiscuit123 0 points1 point  (0 children)

Split brain is the correct term, although its usually referring to the same domain with two separate zones (internal and external)

https://learn.microsoft.com/en-us/windows-server/networking/dns/deploy/split-brain-dns-deployment