Emergency server help: get in touch

DirectAdmin Unbound Resolver: HTTPS and SVCB Records

Installing Unbound through CustomBuild as a caching validating resolver alongside BIND on a DirectAdmin server, pointing the system and ACME checks at it, and publishing HTTPS and SVCB records from DNS Administration.

Published Updated 6 min read

A DirectAdmin server does a great deal of DNS lookup work that customers never see: Exim checks SPF, DKIM and DNSBLs on every message, Rspamd queries several lists per scan, the ACME client validates that a domain points at the server before requesting a certificate, and CSF resolves hostnames for its rules. Sending all of that to a provider’s resolver adds latency and, on busy mail servers, hits DNSBL query limits. CustomBuild can install Unbound as a local caching, DNSSEC-validating resolver. This guide sets it up next to the authoritative BIND service and then covers the HTTPS and SVCB record types that DirectAdmin’s DNS manager can now publish.

Short answer: Run da build set unbound yes and da build unbound so Unbound listens on loopback while BIND keeps the public interfaces, then put nameserver 127.0.0.1 first in /etc/resolv.conf with a fallback and protect the file from the network manager. Enable acme_use_only_system_resolver so certificate checks use the same cache, and add HTTPS records with alpn="h2,h3" from DNS Administration only where the web server really speaks those protocols.

Install Unbound with CustomBuild

The CustomBuild option installs the distribution’s Unbound package and writes a configuration that listens on the loopback address only:

da build set unbound yes
da build unbound
systemctl status unbound

Confirm the option name with da build options on your build. The service listens on 127.0.0.1 and ::1, port 53. BIND continues to listen on the public interfaces for the authoritative zones. Both cannot bind the same address and port, so check that named is not also listening on loopback:

ss -ulnp | grep ':53 '

If BIND holds 127.0.0.1:53, edit /etc/named.conf so listen-on names the public IPs only, then restart named before starting Unbound.

Point the system at it

/etc/resolv.conf needs to name the local resolver first, with the previous resolver retained as a fallback in case Unbound stops:

nameserver 127.0.0.1
nameserver 9.9.9.9
options timeout:2 attempts:2

On AlmaLinux and Debian images the file is often managed by NetworkManager or systemd-resolved, which rewrites it on reboot. Either mark the file immutable with chattr +i, or configure the manager to leave DNS alone; on NetworkManager systems a drop-in with dns=none under /etc/NetworkManager/conf.d/ does that. On Ubuntu with systemd-resolved, set DNS=127.0.0.1 in /etc/systemd/resolved.conf and let the stub forward to Unbound.

The ACME system has its own setting. Since 1.709 acme_use_only_system_resolver makes the pre-issue checks use the resolver in resolv.conf rather than querying authoritative servers directly. With Unbound in place, enabling it means certificate validation sees the same cached, validated answers the rest of the server uses:

da config-set acme_use_only_system_resolver 1

Leave it off on servers behind split-horizon DNS where the local resolver returns private addresses for hosted domains.

Tune the cache for mail workloads

The default Unbound cache is small. For a server handling more than a few thousand messages a day, raise the message and RRset caches and allow prefetching so popular records are refreshed before they expire. Put overrides in /etc/unbound/conf.d/local.conf rather than the CustomBuild-generated file:

server:
    msg-cache-size: 64m
    rrset-cache-size: 128m
    prefetch: yes
    num-threads: 2
    cache-min-ttl: 60

Restart Unbound and confirm the DNSBL lookups Exim performs now hit the cache by running the same query twice and watching the response time drop.

HTTPS and SVCB records

Modern browsers use HTTPS records to learn that a site supports HTTP/2 or HTTP/3 and to obtain the Encrypted Client Hello configuration before the first connection. DirectAdmin’s DNS Administration and the user-level DNS page accept HTTPS and SVCB record types on current builds, and the templates can include a default entry for new zones. A minimal record that advertises HTTP/2 and HTTP/3 for a site served directly by the server looks like this in the zone:

example.com.    3600 IN HTTPS 1 . alpn="h2,h3"
www.example.com. 3600 IN HTTPS 1 . alpn="h2,h3"

Only advertise h3 if the web server actually speaks QUIC; LiteSpeed does, Apache does not. Publishing h3 on an Apache server causes some clients to attempt UDP first and wait for a timeout before falling back.

The record is added in the DNS manager by choosing the HTTPS type, entering the priority 1, the target ., and the parameter string. To add it to the zone template for all new domains, edit /usr/local/directadmin/data/templates/custom/dns_https.conf following the same naming convention as the existing dns_a.conf and dns_mx.conf files, and check the changelog for the exact template name on your build.

Common pitfall: DNSSEC validation breaking upstream lookups

Unbound validates DNSSEC by default. A domain with a broken DNSSEC chain returns SERVFAIL locally even though the provider’s resolver, which may not validate, answered fine. This surfaces as mail bouncing with a temporary DNS failure for one specific domain. Confirm with dig +cd against Unbound, which disables checking; if the answer appears, the remote domain’s DNSSEC is at fault and the correct action is to tell the recipient’s administrator, not to disable validation.

Verify

Check the resolver chain and the new records:

dig +short @127.0.0.1 example.com A
unbound-control stats_noreset | grep -E 'total.num.cachehits|total.num.queries'
dig +short example.com HTTPS
dig +short @ns1.example.net example.com HTTPS

The cache-hit counter should climb steadily on a mail server. For the HTTPS record, compare the answer from a public resolver with the answer from your own nameserver; a mismatch means the zone was edited but not reloaded, which rndc reload example.com fixes. If the server is part of a DNS cluster, confirm the record was pushed to the peers as described in Multi-server DNS clustering on DirectAdmin.

DirectAdmin Unbound resolver at a glance

DirectAdmin Unbound Resolver summary card: Run da build set unbound yes and da build unbound so Unbound listens on loopback while BIND keeps the public…
In short: Run da build set unbound yes and da build unbound so Unbound listens on loopback while BIND keeps the public interfaces, then put nameserver 127.0.0.1 first in /etc/resolv.conf with a fallback and protect the file from the network manager.

Official documentation: CloudLinux documentation, DirectAdmin documentation, Linux man pages.

Related guides: Issuing wildcard certificates with DNS challenges on DirectAdmin · DirectAdmin multi-server setup: DNS clustering and shared user/domain checks · Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation.

Frequently asked questions

Does running Unbound on DirectAdmin interfere with BIND as the authoritative nameserver?

No, provided they listen on different addresses: Unbound on 127.0.0.1 and ::1 and BIND on the public IPs. The only conflict is when named also binds loopback, which the listen-on directive in /etc/named.conf resolves.

How long does it take for Unbound to speed up mail scanning?

The benefit appears within minutes of Exim and Rspamd starting to query it, because DNSBL and SPF answers are cached after the first lookup; the cache-hit counter in unbound-control stats rises steadily on a busy mail server within the first hour.

Can I undo this?

Yes. Restore the previous nameserver lines in /etc/resolv.conf (removing the immutable flag first), set acme_use_only_system_resolver back to 0, then set unbound no in CustomBuild and stop the service; published HTTPS records are deleted from the DNS manager like any other record.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.