What you need to know
Use RFC 4702 — The Dynamic Host Configuration Protocol (DHCP) Client Fully Qualified Domain Name (FQDN) Option to review this narrow operational decision without extending the source beyond its stated scope.
Potentially affected
Teams, systems, services, or facilities within the stated scope of RFC 4702 — The Dynamic Host Configuration Protocol (DHCP) Client Fully Qualified Domain Name (FQDN) Option
DSE recommendation
Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.
Use this document to connect an official requirement or behavior to observable evidence: Assign forward and reverse DNS updates between DHCPv4 client and server. Only the official source and traced locations below supply facts. Confirm applicability before acting.
Source fact:
The official RFC 4702 — The Dynamic Host Configuration Protocol (DHCP) Client Fully Qualified Domain Name (FQDN) Option from RFC Editor / Internet Engineering Task Force supports the following bounded statements:
- In the DHCPv4 Client FQDN option, S requests server responsibility for the A-record update, N requests no server updates, and O reports that the server overrode the requested S value. The research record locates this support at Section 2.1 (The Flags Field).
- A client requesting server-performed forward updates sets S to 1 and sets O and N to 0 in its Client FQDN option. The research record locates this support at Section 3.3 (Client Desires Server to Do DNS Updates).
- When the server returns N=1, the client may originate its own DNS updates after receiving DHCPACK and completing its final parameter checks. The research record locates this support at Section 3.4 (Client Desires No Server DNS Updates).
Keep the evidence boundary at these traced claims. They support a review of authoritative zones, delegations, resolvers, caches, record owners, and the clients that consume the resulting answers; they do not support conclusions outside the source’s stated conditions.
What the source does not establish
This RFC evidence supports only the named DNS protocol decision; it does not prove Windows implementation support or a safe production configuration. It does not establish a deployment’s current state, authorize a production change, prove compliance, or show that Windows DNS roles, Active Directory-integrated data, forwarding paths, time, routing, firewalls, and registrar or registry state are healthy. Documented options are review inputs, not universal mandates.
Applicability questions
- For source statement 1 at Section 2.1 (The Flags Field), which observable configuration, record, or test can confirm applicability here?
- For source statement 2 at Section 3.3 (Client Desires Server to Do DNS Updates), which observable configuration, record, or test can confirm applicability here?
- For source statement 3 at Section 3.4 (Client Desires No Server DNS Updates), which observable configuration, record, or test can confirm applicability here?
- Within authoritative zones, delegations, resolvers, caches, record owners, and the clients that consume the resulting answers, which versions, roles, and configuration states define the review population?
- Could Windows DNS roles, Active Directory-integrated data, forwarding paths, time, routing, firewalls, and registrar or registry state invalidate the test, hide a failure, or change applicability?
- Who owns the decision, and which observation requires stopping, escalation, or rollback?
DSE recommendation:
DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of authoritative zones, delegations, resolvers, caches, record owners, and the clients that consume the resulting answers, observed and expected states, owner, and reason for deviation.
An implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate Windows DNS roles, Active Directory-integrated data, forwarding paths, time, routing, firewalls, and registrar or registry state before and after the test, and store only sanitized operational evidence.
Verification and evidence
Keep the source locations Section 2.1 (The Flags Field); Section 3.3 (Client Desires Server to Do DNS Updates); Section 3.4 (Client Desires No Server DNS Updates) adjacent to the sanitized artifacts used for comparison. Prefer zone data, packet captures, query transcripts, delegation checks, resolver configuration, and negative-answer behavior, with enough identity and timing data for an independent recheck.
Keep before-state evidence, approval, test or change result, exceptions, and after-state evidence together. Use an approved lab, window, or nonproduction path for risky tests. Set a recheck trigger for version, architecture, dependency, vendor, incident, or ownership change. A check proves only what was observed.
Official references
- RFC 4702 — The Dynamic Host Configuration Protocol (DHCP) Client Fully Qualified Domain Name (FQDN) Option — RFC Editor / Internet Engineering Task Force
Review the official source
RFC 4702 — The Dynamic Host Configuration Protocol (DHCP) Client Fully Qualified Domain Name (FQDN) Option · Verified August 26, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE