[SOLVED] Wireshark DNS Flag

Does it work

Jun 3, 2017
Normally packets from a DNS response captured on wireshark are 0x0100 (using UDP.port==53 to single out DNS) a standard response, but recently ran across some captures that were 0x0500, as far as I can tell, this is the bit flag for an AA (authoritative answer), what does it mean when the flag is 0x0500 instead of the usual 0x0100?

Also, is there anything else suspicious I should be looking for?