Beyond filtering, are you looking at your named logs too? There are a
ton of old / misconfigured DNS servers out there that don't support EDNS:
success resolving 'blns71.spamcop.net/A' (in 'spamcop.net'?) after
disabling EDNS success resolving 'bcwww.enet.cu/A' (in 'enet.cu'?) after
reducing the advertised EDNS UDP packet size to 512 octets
success resolving 'hispructs.com/A' (in 'hispructs.com'?) after
reducing the advertised EDNS UDP packet size to 512 octets
You can test for this via this helpful write up:
https://www.dnsoarc.net/oarc/services/replysizetest/
--David