When configuring Reverse DNS zones, the Active Directory Domains for Secure Updates section lists domains that are allowed to send DDNS using GSS-TSIG. Domains in this list are automatically added when Support signed updates from Windows is enabled for the relevant DNS Zones.
You can enable this setting in the Active Directory Service Principal section of the DNS Zone settings.