In extremely busy environments with logging turned on, the number of lines of NXDOMAIN and NOERROR in the logs can be overwhelming. There may be a need to still write to the logs to see what is being blocked by looking at NOERROR. Can a feature be requested to turn of logging of the "NXDOMAIN" to the log file with a flag?
That way the log can still be inspected for IPs that are blocked but the log doesnt get flooded with IPs that are being allowed, which would be a majority of the log lines.