Have we looked at using dnscache[1] for our caching nameserver? It seems more lightweight than using bind (without its track record even!) and seems like exactly what we would want. I haven't looked too much in detail at it (or bind for that matter), but I think its worth considering. I wonder if we would get more widespread adoption for it.

[1] http://cr.yp.to/djbdns/

