RE: I've just tried new.net's plugin. Don't.

DNS cache poisoning as adequately prevented by making your zone servers
non-recursive.