<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.tbpindustries.com/index.php?action=history&amp;feed=atom&amp;title=Unbound</id>
	<title>Unbound - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.tbpindustries.com/index.php?action=history&amp;feed=atom&amp;title=Unbound"/>
	<link rel="alternate" type="text/html" href="https://wiki.tbpindustries.com/index.php?title=Unbound&amp;action=history"/>
	<updated>2026-04-24T04:51:01Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.31.1</generator>
	<entry>
		<id>https://wiki.tbpindustries.com/index.php?title=Unbound&amp;diff=44&amp;oldid=prev</id>
		<title>Goldbolt at 14:35, 3 January 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.tbpindustries.com/index.php?title=Unbound&amp;diff=44&amp;oldid=prev"/>
		<updated>2019-01-03T14:35:24Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 14:35, 3 January 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Unbound is a validating, recursive and caching DNS server designed for high performance. It was released on May 20, 2008 (version 1.0.0) as free software licensed under the BSD license by NLnet Labs, Verisign Inc., Nominet, and Kirei. It is installed as part of the base system in FreeBSD starting with version 10.0, and in NetBSD with version 8.0. A version is also available in OpenBSD version 5.6 and beyond. (Previous versions of FreeBSD shipped with BIND.) The default config file is &amp;lt;code&amp;gt;/usr/local/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in FreeBSD and &amp;lt;code&amp;gt;/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in Linux. Port 53 needs to be open in your router and in the local firewall. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Unbound is a validating, recursive and caching DNS server designed for high performance. It was released on May 20, 2008 (version 1.0.0) as free software licensed under the BSD license by NLnet Labs, Verisign Inc., Nominet, and Kirei. It is installed as part of the base system in FreeBSD starting with version 10.0, and in NetBSD with version 8.0. A version is also available in OpenBSD version 5.6 and beyond. (Previous versions of FreeBSD shipped with BIND.) The default config file is &amp;lt;code&amp;gt;/usr/local/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in FreeBSD and &amp;lt;code&amp;gt;/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in Linux. Port 53 needs to be open in your router and in the local firewall&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;. A better walkthrough is located [https://calomel.org/unbound_dns.html here]&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Goldbolt</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.tbpindustries.com/index.php?title=Unbound&amp;diff=43&amp;oldid=prev</id>
		<title>Goldbolt: Created page with &quot;Unbound is a validating, recursive and caching DNS server designed for high performance. It was released on May 20, 2008 (version 1.0.0) as free software licensed under the BS...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.tbpindustries.com/index.php?title=Unbound&amp;diff=43&amp;oldid=prev"/>
		<updated>2019-01-03T14:31:24Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Unbound is a validating, recursive and caching DNS server designed for high performance. It was released on May 20, 2008 (version 1.0.0) as free software licensed under the BS...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Unbound is a validating, recursive and caching DNS server designed for high performance. It was released on May 20, 2008 (version 1.0.0) as free software licensed under the BSD license by NLnet Labs, Verisign Inc., Nominet, and Kirei. It is installed as part of the base system in FreeBSD starting with version 10.0, and in NetBSD with version 8.0. A version is also available in OpenBSD version 5.6 and beyond. (Previous versions of FreeBSD shipped with BIND.) The default config file is &amp;lt;code&amp;gt;/usr/local/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in FreeBSD and &amp;lt;code&amp;gt;/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; in Linux. Port 53 needs to be open in your router and in the local firewall. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=DNS Resolving Cache=&lt;br /&gt;
&lt;br /&gt;
This can be used as a DNS cache to serve local or external DNS queries. It can also be used to block advertisements. &lt;br /&gt;
&lt;br /&gt;
Custom DNS domains can be set within Unbound as well. This is a basic A record:&lt;br /&gt;
&lt;br /&gt;
       local-data: &amp;quot;xboxone.local IN A 192.168.1.139&amp;quot;&lt;br /&gt;
&lt;br /&gt;
A PTR record can also be set for external queries. Please note that your ISP may block these.&lt;br /&gt;
&lt;br /&gt;
   local-data-ptr: &amp;quot;68.225.35.119 server.domain.com&amp;quot;&lt;br /&gt;
&lt;br /&gt;
A root hints file is required as well. You can &amp;lt;code&amp;gt;wget&amp;lt;/code&amp;gt; this [https://www.internic.net/domain/named.root here]&lt;br /&gt;
&lt;br /&gt;
In order to block most advertisements, &amp;lt;code&amp;gt;include:&amp;lt;/code&amp;gt; is needed. [https://tbpchan.cz/blackhole.zone Here] is the TBP blackhole.zone file for download. Be sure to include it in the &amp;lt;code&amp;gt;/usr/local/etc/unbound/unbound.conf&amp;lt;/code&amp;gt; file. Here's a complete config setup:&lt;br /&gt;
&lt;br /&gt;
    ## Unbound config file&lt;br /&gt;
    server:&lt;br /&gt;
        # Zone file&lt;br /&gt;
    	include: /usr/local/etc/unbound/blackhole.zone&lt;br /&gt;
        # List of valid clients &lt;br /&gt;
    	port: 53&lt;br /&gt;
    	include: /usr/local/etc/unbound/users.conf&lt;br /&gt;
    	# Enable IPv4, &amp;quot;yes&amp;quot; or &amp;quot;no&amp;quot;.&lt;br /&gt;
    	do-ip4: yes&lt;br /&gt;
    	# Enable IPv6, &amp;quot;yes&amp;quot; or &amp;quot;no&amp;quot;.&lt;br /&gt;
    	do-ip6: yes&lt;br /&gt;
    	# Enable UDP, &amp;quot;yes&amp;quot; or &amp;quot;no&amp;quot;.&lt;br /&gt;
    	do-udp: yes&lt;br /&gt;
    	do-tcp: yes&lt;br /&gt;
    	harden-dnssec-stripped: yes&lt;br /&gt;
    	rrset-cache-size: 2048m&lt;br /&gt;
    	msg-cache-size: 1024m&lt;br /&gt;
    	so-rcvbuf: 1m&lt;br /&gt;
    	val-permissive-mode: yes&lt;br /&gt;
        # Verbosity to zero - we don't log&lt;br /&gt;
    	verbosity: 0&lt;br /&gt;
    	use-syslog: no&lt;br /&gt;
        # Specify interfaces&lt;br /&gt;
    	interface: 0.0.0.0&lt;br /&gt;
    	interface: ::0&lt;br /&gt;
        # Our root hints file&lt;br /&gt;
    	root-hints: /usr/local/etc/unbound/root.hints&lt;br /&gt;
        auto-trust-anchor-file: &amp;quot;root.key&amp;quot;&lt;br /&gt;
        # Hide/block identity and version&lt;br /&gt;
    	hide-identity: yes&lt;br /&gt;
    	hide-version: yes&lt;br /&gt;
        # Trust glue only if it is within the servers authority.&lt;br /&gt;
    	harden-glue: yes&lt;br /&gt;
        # Require DNSSEC data for trust-anchored zones&lt;br /&gt;
    	harden-dnssec-stripped: yes&lt;br /&gt;
        # Use 0x20-encoded random bits in the query to help prevent spoofs&lt;br /&gt;
    	use-caps-for-id: yes&lt;br /&gt;
        # Specify caching TTLs&lt;br /&gt;
    	cache-min-ttl: 360&lt;br /&gt;
    	cache-max-ttl: 8640&lt;br /&gt;
        # Perform prefetching of close to expired message cache entries.&lt;br /&gt;
    	prefetch: yes&lt;br /&gt;
    	minimal-responses: yes&lt;br /&gt;
    	qname-minimisation: yes&lt;br /&gt;
    	rrset-roundrobin: yes&lt;br /&gt;
    	num-threads: 8&lt;br /&gt;
        # Do not allow localhost to use the forwarder&lt;br /&gt;
    	do-not-query-localhost: yes&lt;br /&gt;
    	ssl-upstream: yes&lt;br /&gt;
        # Specify servers for forwarding to&lt;br /&gt;
    	forward-zone:&lt;br /&gt;
    		name:&amp;quot;.&amp;quot;&lt;br /&gt;
           	forward-addr: 1.1.1.1@853 	#Cloudflare DNS over TLS&lt;br /&gt;
    	forward-addr: 1.0.0.1@853	#Cloudflare DNS over TLS&lt;br /&gt;
    	forward-addr: 9.9.9.9@853 	#IBM IPv6 Quad9 over TLS&lt;br /&gt;
    	forward-addr: 149.112.112.112@853 	#IBM IPv6 Quad9 over TLS&lt;br /&gt;
    	forward-addr: 2606:4700:4700::1111@853 		#IPv6  Cloudflare DNS over TLS&lt;br /&gt;
    	forward-addr: 2606:4700:4700::1001@853 		#IPv6  Cloudflare DNS over TLS&lt;br /&gt;
    &lt;br /&gt;
    #		forward-addr: 68.1.16.108&lt;br /&gt;
    #		forward-addr: 68.1.16.107&lt;br /&gt;
     #               forward-addr: 208.67.222.222&lt;br /&gt;
     #               forward-addr: 208.67.220.220&lt;br /&gt;
     #               forward-addr: 172.98.193.42&lt;br /&gt;
     #               forward-addr: 192.99.85.244&lt;br /&gt;
     #             forward-addr: 1.1.1.1        # Cloudflare&lt;br /&gt;
     #             forward-addr: 1.0.0.1        # Cloudflare&lt;br /&gt;
     #             forward-addr: 8.8.4.4        # Google&lt;br /&gt;
     #             forward-addr: 8.8.8.8        # Google&lt;br /&gt;
     #             forward-addr: 37.235.1.174   # FreeDNS&lt;br /&gt;
    #             forward-addr: 37.235.1.177   # FreeDNS&lt;br /&gt;
    #              forward-addr: 64.6.64.6      # Verisign&lt;br /&gt;
    #              forward-addr: 64.6.65.6      # Verisign&lt;br /&gt;
    #              forward-addr: 74.82.42.42    # Hurricane Electric&lt;br /&gt;
    #              forward-addr: 84.200.69.80   # DNS Watch&lt;br /&gt;
    #              forward-addr: 84.200.70.40   # DNS Watch&lt;br /&gt;
    #              forward-addr: 91.239.100.100 # censurfridns.dk&lt;br /&gt;
    #              forward-addr: 109.69.8.51    # puntCAT&lt;br /&gt;
    #              forward-addr: 208.67.222.220 # OpenDNS&lt;br /&gt;
    #              forward-addr: 208.67.222.222 # OpenDNS&lt;br /&gt;
    #              forward-addr: 216.146.35.35  # Dyn Public&lt;br /&gt;
    #              forward-addr: 216.146.36.36  # Dyn Public&lt;br /&gt;
    remote-control:&lt;br /&gt;
        # Enable remote control with unbound-control(8) here.&lt;br /&gt;
        # set up the keys and certificates with unbound-control-setup.&lt;br /&gt;
        control-enable: yes&lt;br /&gt;
       &lt;br /&gt;
        # what interfaces are listened to for remote control.&lt;br /&gt;
        # give 0.0.0.0 and ::0 to listen to all interfaces.&lt;br /&gt;
        control-interface: 127.0.0.1&lt;br /&gt;
       &lt;br /&gt;
        # port number for remote control operations.&lt;br /&gt;
        control-port: 8953&lt;br /&gt;
       &lt;br /&gt;
        # unbound server key file.&lt;br /&gt;
        server-key-file: &amp;quot;/usr/local/etc/unbound/unbound_server.key&amp;quot;&lt;br /&gt;
       &lt;br /&gt;
        # unbound server certificate file.&lt;br /&gt;
        server-cert-file: &amp;quot;/usr/local/etc/unbound/unbound_server.pem&amp;quot;&lt;br /&gt;
       &lt;br /&gt;
        # unbound-control key file.&lt;br /&gt;
        control-key-file: &amp;quot;/usr/local/etc/unbound/unbound_control.key&amp;quot;&lt;br /&gt;
       &lt;br /&gt;
        # unbound-control certificate file.&lt;br /&gt;
        control-cert-file: &amp;quot;/usr/local/etc/unbound/unbound_control.pem&amp;quot;&lt;/div&gt;</summary>
		<author><name>Goldbolt</name></author>
		
	</entry>
</feed>