Don't settle for workarounds, go straight to the fix ...
The setting most DNS guides never tell you to check.
I have a 3-site network with S2S IPSec tunnels connecting each to each, as follows: I have Windows Server 2016 and 2022 running AD DS and DNS at the main office, but pfsense doling out DHCP addresses ...