netdom query fsmo
At the same time it is important to test your DCs health.
https://www.alessandromazzanti.com/2015/05/server-commands-to-verify-domain.html.
If you are facing unlike situation that DCs holding all 5 Ad roles (or few of them) are no longer working you should start planning Seizing roles activity.
Here it is a Microsoft article that well apply to all Microsoft Server versions.
https://support.microsoft.com/en-sg/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control
Here they are other important suggests:
- Microsoft best practices suggest to have at least a Physical Domain controller indeed to have all them virtualized:
- I warmly suggest to check all your server and to have local Administrator password (and account enabled).
- To check, on all your servers/Dcs to have indicated DNS1, DNS2 and DNS3 pointing to active DCs/DNS
- Have 5 AD roles splitted between at least two domain controllers.
- About Domain controllers have DRSM Administrator password, if not known proceed to have it resetted.