

And that’s not even letting on that literally ALL DNS queries work from cache unless you are specifically doing a live query.
None of your software is. It’s asking your OS. Your OS is asking your resolver service. Your resolver service is asking your router. Your router is 5000% caching DNS queries.
Nice write up, but there’s just going to be a LOT of false positives.