Just a heads up for anyone using these rules. Due to DNSSEC being switched on in the root name servers, with the rest of the world following shortly: http://tech.slashdot.org/story/10/07/17/0024203/Root-DNS-Zone-Now-DNSSEC-Signed there is a legacy DNS querk where if a reply from a DNS server exceeds...