You can make sure that your DHCP services on your server is set to only respond to the local segment of IP addresses. Also, it is also possible that you have enabled DHCP services to come from your router itself. Be sure that router DHCP services are disabled as this is best practices with a Windows SBS.
Additionally, you should make sure that all incoming ports from the WAN side of your network are blocked except for the ports you want open. For instance, by blocking the port 67 incoming from WAN to LAN/DMZ, you will prevent the request from even reaching your LAN in the first place.