> > An authoritative-only server should only produce the necessary
> > glue:  info about in-zone nameservers, and no other Additional
> > data. 
> So, BIND is wrong?

No, BIND is (per default) not an "authoritative-only server".

BIND is (also) a caching forwarder, and caching forwarders can/may
give back any RRsets it has properly looked up and successfully
cached earlier, when it believes such RRsets may to be relevant to
the requestor (like an A RR to which a CNAME or an MX points).

What a caching forwarder server should NOT do, is to construct
answers using RRsets received as glue on earlier queries. But I
don't think modern BINDs (i.e. later than BIND4) are doing that

