dnscache doesn't fully implement "forwardonly" mode, creating the possibility of other people's published delegation data causing a proxy loop.
This is a critical problem for us.
Created attachment 97528 [details, diff]
This adds the strict-forward-only patch with a useflag, "fwdonly".
Added to -r19, can you test it, please?
Works for me. Thanks!