why does it ever forward odd constructs such as "MachineA.example.net.example.net" to my DoT DNS?
Because some client on your network sends it that question. The recursive nameserver does not add or remove search domains. The resolver libraries on client devices do.HTH,Patrick
Nvm - dug around and found how to constrain the answer using access control view.