> > should you tell bind about the fact the zone "dnsbl" is not using DNSSEC? > > Andreas > A belated thank you for that suggestion, worked nicely as a quick fix although I see there might be better options.