False alarm, it was the proxy on the server that was doing DNS requests. Removed it but still getting the same errors when running the test. Will look more tomorrow. Thanks for your advice, greatly appreciated.
I think I might have found it, there is an old webscan box that no-one else uses any more but it might be that the Unity box never had it's config changed. Will let you know once I know more!!!
Hi Brandon,
Thanks for the links, I can see in the capture file that it is resolving outlook.office365.com to cname outlook-emeawest3.office365.com and returning a number of IPV6 addresses for it. Not sure what it is doing after that though??