We have an Active Directory EC2 server on AWS US East region that has DNS enabled to resolve only internal hostnames. It is not reachable from any hosts on the public internet. Recently we enabled an AWS service called Guard Duty for threat detection and it flagged a finding which indicated our DNS server communicated to a DNS server in Australia (nslookup/whois/nmap all helped to quickly determine the server in AU is indeed a DNS server)
Does anyone know why an internal DNS server would communicate to an external DNS server? Is this normal or does it indicate a problem that might uncover something very bad.
Appreciate any inputs. Thanks!