Incident Overview
You are on call for a hybrid cloud platform. Users report intermittent failures when accessing the internal inventory service inventory.corp.local from branch offices.
Some requests resolve to the correct internal IP 10.20.30.40, while others resolve to the public-facing load balancer IP 203.0.113.10, which rejects internal authentication tokens. The network team confirms that branch offices use a centralised recursive resolver.
The application team insists the service endpoint has not changed. You suspect a DNS configuration drift between the internal authoritative zone and the external public zone.
Investigation Options
Review the available operational moves and select the best immediate action.
Flush the DNS cache on the central recursive resolver.
Compare the serial numbers and zone contents of the internal and external authoritative zones.
Update the public DNS record to match the internal IP address immediately.
Restart the DNS service on the internal authoritative server.