In my /var/log/messages file, in recent days I have been receiving numerous messages such as: Jun 23 15:02:50 OUR-HOST named[577]: sysquery: nslookup reports danger (dns.SUBNET1.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa) Jun 23 15:02:51 OUR-HOST named[577]: sysquery: nslookup reports danger (HOST2.SUBNET2.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa) Jun 23 15:02:51 OUR-HOST named[577]: sysquery: nslookup reports danger (dns.SUBNET3.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa) Jun 23 15:02:51 OUR-HOST named[577]: sysquery: query(dns.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa) A RR negative cache entry (HOST2.SUBNET2.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa:) Jun 23 15:02:51 OUR-HOST named[577]: sysquery: query(dns.OTHER.DOMAIN.AAA.BBB.CCC.in-addr.arpa) No possible A RRs I''m curious as to what might be causing this. Last night, over a span of 15 minutes, I got nearly 1000 of these messages in my log file. Is it a problem with one (or more) of their hosts, is someone spoofing DNS requests using their subnet, or is it a problem with my DNS configuration? I''m running RedHat 5.0 with bind-4.9.6-7. Any insight would be greatly appreciated. Dan Cornell dan@atension.com