hi @00pflaume welcome to the community
you don’t want to have such setup. reasons have been often discussed.
the solution is to use public domain internally as well but avoid the loop using “Split brain DNS” splitbraindns e.g. like explained here Lost acces from inside LAN - #14 by wwe