I have submitted a ticket to reduce or eliminate sending the *.local.mesh DNS queries out the WAN interface in the absence of a tunnel being configured to receive them - they're entirely unresolvable that way, and I'm seeing thousands of them heading out that interface.
http://bloodhound.aredn.org/products/AREDN/ticket/248
http://bloodhound.aredn.org/products/AREDN/ticket/248
local=/local.mesh/
...to /etc/dnsmasq.conf