It's become apparent that about 90% of the incoming external DNS requests are being blocked at the firewall.
Config:
Our public NS1 is a Windows 2012R2 server, running in a DMZ. There is a simple DNAT rule (Any -> DNS -> External IP ==> Change dest…