> Or else set up secure proxies and disallow all DNS resolution (an > empty root zone). I'm not sure what you mean by "secure proxies". Do you mean some non-BIND software capable of forwarding and filtering DNS queries/responses? If so, do you have anything particular in mind? Thanks, Brian.