Programmable DNS error code in response to DNS query
The DNS queries for blocklisted domains which are of SRV and TXT query types, you can specify a TXT or SRV response code in the DNS response with an empty answer section. To specify the response code, configure the txt-resp-err-code or srv-resp-err-code option at the [edit services web-filter profile profile-name dns-filter-template template-name] hierarchy level. For both the options, if you configure Noerror as the value, the error code is sent as 0 with an empty response; whereas, if you set Refusederror as the value, the error code is sent as 5.