I'm not a DNS guru so forgive me if these are silly questions

but I did not find anything in the manuals or forum that matched my situation.
We have a hosted doman
Domain.com for our customers. I would like to setup a subdomain
Internal.Domain.com as a VPN to link our 3 offices and 20+ remote users. I would also like to host e-mail as
Domain.com. I do not want all
Domain.com traffic to be sent to my office server. I just want the MX records for
Domain.com and the subdomain
Internal.Domain.com (webmail via mail.internal... is fine). Everything else should go to the web hosting service.
I know I can direct the email using an MX record and the subdomain using an ANAME to the onsite server. My question is, should I setup the onsite server as
Domain.com and add
Internal.Domain.com or visa-versa? Or am I totally off base?