our stock /var/lib/bind/etc/options.conf should include commented-out line like this: allow-recursion { 127.0.0.0/8; 10.0.0.0/8; }; to help system administrators set up name servers in non-world-recursive manner.
another candidate could be: // max-cache-ttl 86400;
http://securityfocus.com/archive/1/336987 could be "gently pushed" in stock zone files too, being proper example.
Implemented in -9.2.3.rc1-alt2
closing