# Unbound

> Validating recursive DNS resolver with DNSSEC support. Use when setting up private recursive DNS, validating DNSSEC signature chains, configuring DNS-over-TLS forwarding, serving as Pi-hole upstream resolver, or managing local DNS zones.

- Skill: `bytesagain/unbound` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add bytesagain/unbound`
- Raw SKILL.md: https://api.skillmd.com/api/skills/bytesagain/unbound/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: bytesagain (https://skillmd.com/u/bytesagain)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/bytesagain/unbound

---


# Unbound Reference

Validating recursive DNS resolver that queries root servers directly without forwarding to third-party DNS providers. Unbound validates DNSSEC signatures to protect against DNS spoofing and runs with minimal resources on any Linux system or Raspberry Pi.

## When to Use

- Setting up a private recursive DNS resolver (no forwarding to Google/Cloudflare)
- Validating DNSSEC signature chains for DNS security
- Configuring DNS-over-TLS for encrypted upstream forwarding
- Using as Pi-hole upstream resolver for ad blocking with full privacy
- Managing local DNS zones and custom DNS records
- Monitoring DNS cache performance and query statistics

## Commands

| Command | Description |
|---------|-------------|
| `intro` | Architecture overview, Unbound vs BIND vs Pi-hole comparison, installation |
| `config` | unbound.conf directives, recursive vs forwarding mode, local zones, Pi-hole integration |
| `operations` | unbound-control CLI, DNSSEC testing and validation, cache management, Prometheus monitoring |

## Requirements

- No external dependencies — outputs reference documentation only
- No API keys required

## Feedback

https://bytesagain.com/feedback/

