> The resolver is used by customers who sometimes leak RFC1918 requests
> to our resolver. I already told them to resolve that network
> internally, but still the IANA server is not working correctly IMHO.
> I'm also thinking about routing the blackhole /24 to one of our
> DNS-Servers to resolve all of the RFC1918 space locally, but that will
> take a little bit more time.

Just add zones,, and
{16-31} to ALL of your resolving name servers, pointing
to a file that only has NS and SOA records.

Or a "* IN PTR not-a-working-address." record.  ;-)

Or if you want to preserve the purity of separation of your resolvers
and authoritative name servers, do the above on one or more of your
authoritative name servers, and make them "forward only" zones on your
resolvers, pointing them to the authoritative name servers that have
been so favoured.

It takes less time than reading this mailing list!  ;-)

