It's no easy to block my clients and ask them to clean up their machines.
They will switch to another service instead of cleaning.


Im running 20 Unbound servers and around 20% of response are NXDOMAIN, for 
queries coming from my clients.

Block those IPs that are obviously p4wned until they clean up their PCs?

