Hi Bowie, thanks for your reply.
I would suggest temporarily removing the forward completely as a test and see if this fixes the problem. If so, then your exemptions are not working correctly. If not, then double-check that you are actually using the local server and not still querying the ISP's server.
I did exactly this the last hours and let spam reach my box during that time. When forwarding is disabled completely, the DNSBL services work. So, as you said, something's not OK with the exemptions.
This makes me wonder a bit, since these are described on the SA wiki site http://wiki.apache.org/spamassassin/CachingNameserver#Non-forwarding and they were copied 1:1 into my setup.
I'll try to find out what's wrong in the Bind-community, too. Best regards, Marc