After you have configured DNS sinkholing and
verified that traffic to a malicious domain goes to the sinkhole
address, you should regularly monitor traffic to the sinkhole address,
so that you can track down the infected hosts and eliminate the
threat.