And in response to your actual question (you don't expect me to read things, surely!), since those seem to be coming in at quite a rate, why not just tcpdump/wireshark DNS traffic coming into the name server for a few minutes, and dig out the queries from there? Nigel.