Better RRL?
In current implementation of RRL can not been set limits to different responses, set "whitelist" subnets or calculate limits per specified prefix-length. For example my configuration from Bind 9:
rate-limit { responses-per-second 15; errors-per-second 5; nxdomains-per-second 5; slip 2; window 10; ipv4-prefix-length 24; exempt-clients { 203.0.113.1/32; }; };