←back to thread

220 points speckx | 1 comments | | HN request time: 0.205s | source
Show context
thedanbob ◴[] No.45143600[source]
I set up authoritative nameservers at home using unbound, which appears to be considerably easier than configuring BIND, but I still can't say that I fully understand it. DNS (and networking in general) is a bit of a dark art.
replies(8): >>45144024 #>>45144179 #>>45144184 #>>45144578 #>>45144619 #>>45145306 #>>45146196 #>>45148030 #
1. TacticalCoder ◴[] No.45145306[source]
I run unbound at home too.

To me a huge benefit of unbound is that it allows to return whatever you want for wildcards.

Including TLD wildcards.

Seychelles DNS has been hijacked as a whole and only serves malware? Null route the entire .sc.

.ru ? Nah, that won't resolve at my place.

etc.

Then unbound is at ease, even on an old Raspberry Pi, with blocklists made of hundreds of thousands of lines.