All DNS resolvers discovered on our network belong to customers. Our own resolvers, running unbound, were not discovered.
While filtering same AS on ingress could help those customers (but only one was a open relay), filtering bogons is something the customer can also do. Or the software can be fixed. Do we really expect the ISP to implement firewalls instead of customers upgrading software?
I also note that apparently our own ISPs (transits) do not filter bogons either.
The above is a principal question. I am going to filter bogons, it just is not very high on my long list of stuff to do.
Regards
Baldur