|
|
|
|
|
by chrissnell
1562 days ago
|
|
The way I handle this is to run unbound on a server in the public cloud and then tunnel over TLS from my local unbound to the cloud instance. My local clients query a PiHole, which forwards to unbound on localhost:15353, which forwards everything over TLS to the fully recursive instance of unbound in the cloud, which uses root.hints. |
|
But someone can see it, but you can rotate upstream resolvers to split requests if you have to.