first some remarks on the failed attempt
That doesnt make sense. If you really want to provide the forward zone for “domain.com” you should point to a name server you have under your control. In this case, and especially if you want to provide an A-record for mx1.domain.com by using an IP managed client this should be the UCS.
There is no need to create a reverse zone for this task.
There is some explanation of the behaviour in https://docs.software-univention.de/manual-4.3.html#computers:Configuring_the_name_servers
This means that you should rather try to configure dns/forwarder1
(and additional ones) by using the DNS provided by your internet provider or, in case you really want to feed Google, 8.8.8.8. (1.1.1.1 and 9.9.9.9 are other common public DNS servers).
After changing these UCR variables you have to restart the “bind9” service.
I’d recommend to use tools like host
or dig
to check if the name resolution is working instead of looking into application logs.