Try again with these settings. 
auth-nxdomain no;   
dnssec-validation no;
I suggest review you settings 
https://wiki.samba.org/index.php/BIND9_DLZ_AppArmor_and_SELinux_Integration 
Stop and start bind and samba (first bind) 
Try again. 
Greetz, 
Louis 
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens 
> Hajdu Szabolcs via samba
> Verzonden: dinsdag 22 januari 2019 7:36
> Aan: samba at lists.samba.org
> Onderwerp: Re: [Samba] samba_dns_question
> 
> here is my smb.conf:
> 
> # Global parameters
> [global]
>          netbios name = AD1
>          realm = KVM.DOMAIN.RO
>          server role = active directory domain controller
>          server services = s3fs, rpc, nbt, wrepl, ldap, cldap, kdc, 
> drepl, winbindd, ntp_signd, kcc, dnsupdate
>          workgroup = KVM
> 
> [netlogon]
>          path = /var/lib/samba/sysvol/kvm.domain.ro/scripts
>          read only = No
> 
> [sysvol]
>          path = /var/lib/samba/sysvol
>          read only = No
> 
> my named.conf.options only this is changed ubuntu pulls it a 
> part with 
> includes but only this was modified:
> 
> options {
>      directory "/var/cache/bind";
> 
>       forwarders {
>           208.67.222.222; 208.67.220.220;
>       };
>      dnssec-validation auto;
> 
>      auth-nxdomain no;    # conform to RFC1035
>      listen-on-v6 { any; };
>      notify no;
>      empty-zones-enable no;
>      tkey-gssapi-keytab "/var/lib/samba/private/dns.keytab";
> };
> 
> dlz "AD DNS Zone" {
>       database "dlopen 
> /usr/lib/x86_64-linux-gnu/samba/bind9/dlz_bind9_11.so";
> };
> 
> Szabolcs
> 
> 
> 
> -- 
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>