Well I've carried out the IPTraf report and it showed me loads of outbound requests on port 53 from my SME server (as expected). Unfortunately there is no matching high number of requests from any of our workstations.
This suggests to me that the requests are being generated by the server itself. The fact that the lookups are failing and are to one address parysecund.com suggests that maybe the system is just continually asking for the same address lookup as it hasn't had an answer. I don't know if that's how it works but, if it is the case, is there any way I can clear the dodgy domain name from it's cache and thereby stop it looking it up?
Regards
Mike