I've already been receiving case randomization from them for some time. Perhaps my poor little DNS servers are being used as a test case? Or do they pass along randomization from Tor exit nodes when those nodes are using Google's open resolvers?
It must be Tor. The UDP TTL of those requests is usually 200+ whereas the lower case requests are below 128 UDP TTL. Not DNS TTL
It must be Tor. The UDP TTL of those requests is usually 200+ whereas the lower case requests are below 128 UDP TTL. Not DNS TTL