I've become aware that using the "allow-transfer" directive in a zone definition does not prevent someone from pulling all A records in a zone by using "host -l domain". Is there a way to prevent that?