Resolved! DNS sinkhole database view or test
We are finding that even domains configured as malware/c2 are not getting sinkholed. I'm aware from other posts, that these are not the same database on the firewall.
Why are these not persistent? Why would you not flag on a DNS lookup that is
...