I was able to fix this without having TAC do some intensive backdoor actions. Go to FTD command line system support diagnostic-cli enable (if needed) show run look for the dns policy map. Mine was similar to: policy-map type inspect dns preset_dns_m...