modules/policy: DENY home.arpa. special-use domain

Well, it's just an approximation... if the user specifies a forwarding
policy, any special names will also get forwarded, even though the RFC
says not to.  And this code will also reply NXDOMAIN to home.arpa. DS.

For local. we kept the default behavior, after some research,
as there seems almost no benefit and there's risk of having
a validating resolver downstream that doesn't treat local.  Refs.:
- home.arpa.: 4. from https://tools.ietf.org/html/rfc8375#section-4
- local.: 4. from https://tools.ietf.org/html/rfc6762#section-22.1
28 jobs for policy-special-use-dnames
in 46 minutes and 30 seconds and was queued for 2 seconds