DNS failed to bind to the Domain Controller's IP address during startup, causing a cascade of AD and DNS registration failures.

Keith Gauci 0 Reputation points
2026-10-06T13:48:00.58+00:00

Hi everyone,

Sorry for the long post.

I’m seeing the same issue on multiple environments with Windows Server 2022 Domain Controllers running as Hyper-V VMs.

Sometimes after a reboot, DNS logs the following events:

  • DNS 404 (Winsock error10049 / WSAEADDRNOTAVAIL)
  • DNS 407
  • DNS 408
  • DNS 4013 (DNS could not immediately bind and synchronize)
  • Netlogon 5774 (Netlogon failed to register critical DNS records)
  • DHCP 20322 - (DHCP experienced authorization / registration issues.

As a result, users are unable to work.

What’s confusing is that this doesn’t happen on every reboot. When it happens, we reboot the server again and then it works normally.

The logs make it look like DNS is unable to bind to its own IP address during startup, which then causes the AD, Netlogon and DHCP related errors that follow.

Some info:
Hosts: I've seen it happening on HP ProLiant DL385 Gen10 Plus v2and HP ProLiant DL380 Gen11

  • All clients have only one DC. Unfortunately, it is difficult to add more.
  • DNS server is listening to the actual server IP.
  • The primary DNS server configured on the network card is the server IP.
  • IPv6 on the network card is enabled
  • The Hyper-V virtual network adapter loads in the same order in both cases: during a problematic reboot and during a successful reboot

Has anyone experienced this before?

Windows for business | Windows Server | Directory services | Active Directory
0 comments No comments

1 answer

Sort by: Most helpful
  1. VPHAN 45,420 Reputation points Independent Advisor
    2026-10-06T14:45:00.52+00:00

    Hi Keith Gauci,

    The failure after rebooting is caused by a startup race condition between the DNS Server service and the virtual network adapter. On high-speed host hardware like your HPE ProLiant Gen10 Plus and Gen11 servers, the operating system boots so rapidly that the DNS service executable at %SystemRoot%\System32\dns.exe launches before the Hyper-V network driver (%SystemRoot%\System32\drivers\netvsc.sys) finishes Duplicate Address Detection on the virtual network card. Because the DNS server is configured to listen only on the server's specific IP address rather than all available interfaces, Windows stores that IP address in the ListenAddresses value under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters. When dns.exe attempts to bind its network sockets exclusively to that IP address while the operating system is still verifying that no other device is using it, Windows rejects the request with Winsock error 10049 (WSAEADDRNOTAVAIL, meaning the requested address is not yet available). This logs DNS Event IDs 404 for TCP, 407 for UDP, and 408 for the failed socket. DNS service does not retry binding to that specific IPv4 address after the network finishes initializing, Active Directory cannot locate its zone (DNS Event ID 4013), the Netlogon service inside %SystemRoot%\System32\lsass.exe cannot register the domain locator records listed in %SystemRoot%\System32\Config\netlogon.dns (Netlogon Event ID 5774), and the DHCP Server service fails its Active Directory authorization check (DHCP Event ID 20322).

    You need to configure the DNS service to listen on all IP addresses rather than binding to a specific IP address. Open the DNS Manager console by launching %SystemRoot%\System32\dnsmgmt.msc, right-click your server name, select Properties, open the Interfaces tab, and switch the selection to All IP addresses. Applying this setting deletes the restrictive ListenAddresses value from HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters. This allows the DNS service to bind to the wildcard addresses 0.0.0.0 for IPv4 and :: for IPv6, which succeeds immediately during early boot without waiting for the virtual adapter to complete Duplicate Address Detection. Do not configure the DNS Server service for delayed automatic startup; delaying DNS on a sole Domain Controller will starve dependent Active Directory and Netlogon services of name resolution during boot. Finally, keep IPv6 enabled on the network adapter to maintain official Microsoft Domain Controller compliance, and verify inside Network Connections (%SystemRoot%\System32\ncpa.cpl) that the adapter lists the server's static IP as the primary DNS server alongside the loopback address 127.0.0.1 (and ::1 for IPv6) to ensure consistent local name resolution.

    Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.

    VPHAN

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.