Idiot changed his source address, maybe because he saw his traffic getting ignored. I think it's a small business or something.
But I figured out how to setup the ACLs. Now a tcpdump shows a steady stream of "DNS Refused" packets. :-)
If I want to do dastardly resolutions, I need to brush up on my zone file syntax.
Wade.