n.b. it's a double-pointer. The /called/ code probably allocates a dns_name_t itself, updating the /callee's/ pointer. If the callee's pointer isn't NULL, there's a chance overwriting it will cause a memory leak (as the caller may no longer have a reference to whatever it was pointing to). The comment acknowledges that it's perhaps unnecessarily strict.
Hrm, it was a worthwhile check imho. Without the check, the memory leak you've indicated would have allowed the same packet to cause an out-of-memory DOS.
Working within the constraints of a lower level language where it's difficult (you could use a struct, often in a typedef, but then all callers would need to unpack/work with it...) to return arbitrary tuples of data.