Hmm - I would assume the opposite. Most people would run SA in DMZes wouldn't they? And most DMZ design philosophies are that DMZ hosts should attempt to have near-zero access to internal resources. i.e. no internal DNS.
Why would you be sending internal domain names through your external SA? If you send to another internal user who might use a VPN from outside, you still send to his internal address.