You can use dcdiag to perform the DNS test against your DCs. More here: https://technet.microsoft.com/en-us/library/cc776854%28v=ws.10%29.aspx
I would highly recommend using the IP settings I shared here as using them fixes most of the known DNS resolution issues in AD domains: http://www.ahmedmalek.com/web/fr/articles.asp?artid=23
Also, use dcdiag and repadmin to make sure that your DCs are in a healthy state and that your AD replication is okay. As for your NPS servers, make sure that they point only to your DNS servers for DNS resolution. You can get more details about the failure by checking events in event v