Your PC's should only be using the local DNS (AD server). Your DNS server should be set to forward requests it can't answer to your ISP. I use opendns myself. If you don't do it this way, you are just asking for trouble in an AD environment.