Bind returns via Round Robin. Samba Internal DNS does not -- it is sequential (I don't know how it is weighted). It is exactly this reason -- referring to ldaps://ad.mydomain.tld and trusting DNS to eventually return all of the DC's -- that I switched to Bind.