Thats why I said the DNS section was a "cop out". The DNS
information hadn't been collected, distilled and put on
paper. I attempted to do that.
* Don't publish ambigious addresses global.
* It is unwise (but not wrong) to publish unreachable addresses.
* Don't let reverse queries for private address space leak.
That it is common to leak the private net next to you and
you should stop that as well as what you are using.
* That you can the apex of the reverse zone for private space
to create your own deleation tree (e.g. 10.in-addr.arpa,
168.192.in-addr.arpa) and not have to slave all the reverse
zones everywhere.