Of course, my suggestion was made in jest. However... given that ISPs are already breaking DNS by replacing NXDOMAIN responses with forged records... would we not all be better off if they were allowed to do so by the protocol? As long as there was a flag in each RR indicating that it is an advertising result, users of web browsers could opt in/out of receiving them, and other programs could ignore them altogether. At least we'd be in a better situation to that which we are in now. Of course, DNSSEC presumably fixes all of this, but not in favour of those who are incentivized to present the forged advertising responses.