Currently if you send a DNS query to defensx and it is from an unregistered IP it blocks the dns query/fails closed. This can cause disruption to our clients if the IP address or ISP is changed without our knowledge. it would be less frictious if there was the option on one or more of the ip pairs to respond to dns requests even if it is from a network not registered in the portal.