What is auth-nxdomain?

Name servers set the AA bit when they send an authoritative answer: ie
the server is master or slave for the zone relating to the query. They
also send an NXDOMAIN error response if the name being looked up does
not exist. So this option in BIND9 means that you have the ability to
change the default behaviour if you really care. (Which you probably
don't unless you've got ancient DNS clients that are long overdue for
upgrade and misbehave when they get a reply with bith an NXDOMAIN error
code and the AA bit set.)

