If the Active Roles Synchronization Service has an Active Directory Connection defined for a separate forest
contoso.lan, the Sync Service initially submits the following DNS query for an SRV record in:
_ldap._tcp.ADSite01._sites.gc._msdcs.contoso.lan
If there happens to be an Active Directory Site in DNS with that same name in contoso.lan, then the Sync Service will use the first Active Directory Domain Controller in the response. If this query fails, then a more general DNS query is issued:
_ldap._tcp.gc._msdcs.contoso.lan.