A DirectAdmin server does a great deal of DNS lookup work that customers never see: Exim checks SPF, DKIM and DNSBLs on every message, Rspamd queries several lists per scan, the ACME client validates that a domain points at the server before requesting a certificate, and CSF resolves hostnames for its rules. Sending all of that to a provider’s resolver adds latency and, on busy mail servers, hits DNSBL query limits. CustomBuild can install Unbound as a local caching, DNSSEC-validating resolver. This guide sets it up next to the authoritative BIND service and then covers the HTTPS and SVCB record types that DirectAdmin’s DNS manager can now publish.
Table of Contents
Short answer: Run da build set unbound yes and da build unbound so Unbound listens on loopback while BIND keeps the public interfaces, then put nameserver 127.0.0.1 first in /etc/resolv.conf with a fallback and protect the file from the network manager. Enable acme_use_only_system_resolver so certificate checks use the same cache, and add HTTPS records with alpn="h2,h3" from DNS Administration only where the web server really speaks those protocols.
Install Unbound with CustomBuild
The CustomBuild option installs the distribution’s Unbound package and writes a configuration that listens on the loopback address only:
da build set unbound yes
da build unbound
systemctl status unbound
Confirm the option name with da build options on your build. The service listens on 127.0.0.1 and ::1, port 53. BIND continues to listen on the public interfaces for the authoritative zones. Both cannot bind the same address and port, so check that named is not also listening on loopback:
ss -ulnp | grep ':53 '
If BIND holds 127.0.0.1:53, edit /etc/named.conf so listen-on names the public IPs only, then restart named before starting Unbound.
Point the system at it
/etc/resolv.conf needs to name the local resolver first, with the previous resolver retained as a fallback in case Unbound stops:
nameserver 127.0.0.1
nameserver 9.9.9.9
options timeout:2 attempts:2
On AlmaLinux and Debian images the file is often managed by NetworkManager or systemd-resolved, which rewrites it on reboot. Either mark the file immutable with chattr +i, or configure the manager to leave DNS alone; on NetworkManager systems a drop-in with dns=none under /etc/NetworkManager/conf.d/ does that. On Ubuntu with systemd-resolved, set DNS=127.0.0.1 in /etc/systemd/resolved.conf and let the stub forward to Unbound.
The ACME system has its own setting. Since 1.709 acme_use_only_system_resolver makes the pre-issue checks use the resolver in resolv.conf rather than querying authoritative servers directly. With Unbound in place, enabling it means certificate validation sees the same cached, validated answers the rest of the server uses:
da config-set acme_use_only_system_resolver 1
Leave it off on servers behind split-horizon DNS where the local resolver returns private addresses for hosted domains.
Tune the cache for mail workloads
The default Unbound cache is small. For a server handling more than a few thousand messages a day, raise the message and RRset caches and allow prefetching so popular records are refreshed before they expire. Put overrides in /etc/unbound/conf.d/local.conf rather than the CustomBuild-generated file:
server:
msg-cache-size: 64m
rrset-cache-size: 128m
prefetch: yes
num-threads: 2
cache-min-ttl: 60
Restart Unbound and confirm the DNSBL lookups Exim performs now hit the cache by running the same query twice and watching the response time drop.
HTTPS and SVCB records
Modern browsers use HTTPS records to learn that a site supports HTTP/2 or HTTP/3 and to obtain the Encrypted Client Hello configuration before the first connection. DirectAdmin’s DNS Administration and the user-level DNS page accept HTTPS and SVCB record types on current builds, and the templates can include a default entry for new zones. A minimal record that advertises HTTP/2 and HTTP/3 for a site served directly by the server looks like this in the zone:
example.com. 3600 IN HTTPS 1 . alpn="h2,h3"
www.example.com. 3600 IN HTTPS 1 . alpn="h2,h3"
Only advertise h3 if the web server actually speaks QUIC; LiteSpeed does, Apache does not. Publishing h3 on an Apache server causes some clients to attempt UDP first and wait for a timeout before falling back.
The record is added in the DNS manager by choosing the HTTPS type, entering the priority 1, the target ., and the parameter string. To add it to the zone template for all new domains, edit /usr/local/directadmin/data/templates/custom/dns_https.conf following the same naming convention as the existing dns_a.conf and dns_mx.conf files, and check the changelog for the exact template name on your build.
Common pitfall: DNSSEC validation breaking upstream lookups
Unbound validates DNSSEC by default. A domain with a broken DNSSEC chain returns SERVFAIL locally even though the provider’s resolver, which may not validate, answered fine. This surfaces as mail bouncing with a temporary DNS failure for one specific domain. Confirm with dig +cd against Unbound, which disables checking; if the answer appears, the remote domain’s DNSSEC is at fault and the correct action is to tell the recipient’s administrator, not to disable validation.
Verify
Check the resolver chain and the new records:
dig +short @127.0.0.1 example.com A
unbound-control stats_noreset | grep -E 'total.num.cachehits|total.num.queries'
dig +short example.com HTTPS
dig +short @ns1.example.net example.com HTTPS
The cache-hit counter should climb steadily on a mail server. For the HTTPS record, compare the answer from a public resolver with the answer from your own nameserver; a mismatch means the zone was edited but not reloaded, which rndc reload example.com fixes. If the server is part of a DNS cluster, confirm the record was pushed to the peers as described in Multi-server DNS clustering on DirectAdmin.
DirectAdmin Unbound resolver at a glance

Official documentation: CloudLinux documentation, DirectAdmin documentation, Linux man pages.
Related guides: Issuing wildcard certificates with DNS challenges on DirectAdmin · DirectAdmin multi-server setup: DNS clustering and shared user/domain checks · Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation.
Frequently asked questions
Does running Unbound on DirectAdmin interfere with BIND as the authoritative nameserver?
No, provided they listen on different addresses: Unbound on 127.0.0.1 and ::1 and BIND on the public IPs. The only conflict is when named also binds loopback, which the listen-on directive in /etc/named.conf resolves.
How long does it take for Unbound to speed up mail scanning?
The benefit appears within minutes of Exim and Rspamd starting to query it, because DNSBL and SPF answers are cached after the first lookup; the cache-hit counter in unbound-control stats rises steadily on a busy mail server within the first hour.
Can I undo this?
Yes. Restore the previous nameserver lines in /etc/resolv.conf (removing the immutable flag first), set acme_use_only_system_resolver back to 0, then set unbound no in CustomBuild and stop the service; published HTTPS records are deleted from the DNS manager like any other record.