We have lots of clients on Wide Area Networks..(WANs)..and (Campus Area Networks (CANs)
For smaller ones..with just a couple of PCs at the satellites, we set their primary DNS to be the IP of the DC which is at "mothership". It hits that through the VPN tunnel.
Obviously the faster the connections at all sites, the better. Including upload at mothership of course....since that is download for the satellites.
For PCs at satellite offices, if you have GPOs for redirected user profiles....obviously you want to cut back on that for the branch office PCs...unless you have a fat pipe. Else log ins will be very slow.
Once you get larger numbers of workstations at the satellite offices, obviously it's better to have another DC there..replicating with motherships DC. Helps speed up log ins and allow folder redirection. Speeds up their web surfing too since the DNS request doesn't have to travel through a VPN tunnel.