Let's identify it and get it filed. Can you paste the relevant part of your config file? Feel free to sanitize sensitive parts like hostnames, etc. What is the desired order of resolving? SRV first, then hardcoded host name?
Yes, it is quite confusing to me.....Please note that the difference in requiring the realm in the LDAP and Kerberos providers in tracked by https://fedorahosted.org/sssd/ticket/570 which is currently deferred, but maybe it is time to reconsider it given it is confusing our users.
Given the TXT realm discovery can potentionally be dangerous, I think it needs to be explicitly turned on by specifying 'krb5_realm = _txt_' similar to how can one specify SRV lookups.