There are places that views/split-horizon fit the model that has been put into place.  It does, however, break the "one-question, one-answer" concept that was foundational for DNS.

My recommendation is that for "internal" addressing, a separate zone be created that serves that address space.  You gain a number of things from this, including easier debugging and better data security (no-longer are you concerned about exactly what clients are seeing at "" since you know that the only people able to resolve/route "" are the ones that should be able to).

The problem lies in that over the years, people (usually the higher-ups) have been trained (by us, the in-the-trench guys) that "" can be one thing internally and something else externally, or that their printer really _should_ be named and not

