WIP: modules/policy: DENY forgotten special-use domains
- local.: 4. from https://tools.ietf.org/html/rfc6762#section-22.1
- home.arpa.: 4. from https://tools.ietf.org/html/rfc8375#section-4
Well, it's just an approximation... if the user specifies a forwarding policy, any special names will also get forwarded, even though the RFC says not to. And this code will also reply NXDOMAIN to home.arpa. DS.
It's not clear whether denying local. locally without a DNSSEC proof is actually better, especially when QNAME minimization is employed...