doktor5000 wrote:By using tcpdump or similar and filtering for the DNS name, IP adresses or for port 53 ?
Thank you! After a long time searching it turned out to be very simple: one user occasionally started a virtual machine which is using the hosts IP address to connect to the internet (NAT). And whenever the internet explorer was running in that vm there were regular attempts to contact "bing.com". After disabling that option within internet explorer the dns queries disappeared.