Over-dependency on BIND

Tomorrow, I’m upgrading the external DNS server to bind9. This will be the second time I’ve upgraded in as many years because of security problems. It turns out I could have simply disabled lookups for zones that the box is not authoritative for, but we should probably move to bind9 anyway.

