# DirectAdmin Unbound Resolver: HTTPS and SVCB Records

Source: https://srvscripts.com/guides/directadmin-unbound-resolver-https-svcb/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A DirectAdmin server does a great deal of DNS lookup work that customers never see: Exim checks SPF, DKIM and DNSBLs on every message, Rspamd queries several lists per scan, the ACME client validates that a domain points at the server before requesting a certificate, and CSF resolves hostnames for its rules. Sending all of that to a provider’s resolver adds latency and, on busy mail servers, hits DNSBL query limits. CustomBuild can install Unbound as a local caching, DNSSEC-validating resolver. This guide sets it up next to the authoritative BIND service and then covers the HTTPS and SVCB record types that DirectAdmin’s DNS manager can now publish.

In short: Run da build set unbound yes and da build unbound so Unbound listens on loopback while BIND keeps the public interfaces, then put nameserver 127.0.0.1 first in /etc/resolv.conf with a fallback and protect the file from the network manager.

**Short answer:** Run `da build set unbound yes` and `da build unbound` so Unbound listens on loopback while BIND keeps the public interfaces, then put `nameserver 127.0.0.1` first in `/etc/resolv.conf` with a fallback and protect the file from the network manager. Enable `acme_use_only_system_resolver` so certificate checks use the same cache, and add `HTTPS` records with `alpn="h2,h3"` from DNS Administration only where the web server really speaks those protocols.

## Install Unbound with CustomBuild

The CustomBuild option installs the distribution’s Unbound package and writes a configuration that listens on the loopback address only:

```
da build set unbound yes
da build unbound
systemctl status unbound
```

Confirm the option name with `da build options` on your build. The service listens on `127.0.0.1` and `::1`, port 53. BIND continues to listen on the public interfaces for the authoritative zones. Both cannot bind the same address and port, so check that `named` is not also listening on loopback:

```
ss -ulnp | grep ':53 '
```

If BIND holds `127.0.0.1:53`, edit `/etc/named.conf` so `listen-on` names the public IPs only, then restart `named` before starting Unbound.

## Point the system at it

`/etc/resolv.conf` needs to name the local resolver first, with the previous resolver retained as a fallback in case Unbound stops:

```
nameserver 127.0.0.1
nameserver 9.9.9.9
options timeout:2 attempts:2
```

On AlmaLinux and Debian images the file is often managed by NetworkManager or systemd-resolved, which rewrites it on reboot. Either mark the file immutable with `chattr +i`, or configure the manager to leave DNS alone; on NetworkManager systems a drop-in with `dns=none` under `/etc/NetworkManager/conf.d/` does that. On Ubuntu with systemd-resolved, set `DNS=127.0.0.1` in `/etc/systemd/resolved.conf` and let the stub forward to Unbound.

The ACME system has its own setting. Since 1.709 `acme_use_only_system_resolver` makes the pre-issue checks use the resolver in `resolv.conf` rather than querying authoritative servers directly. With Unbound in place, enabling it means certificate validation sees the same cached, validated answers the rest of the server uses:

```
da config-set acme_use_only_system_resolver 1
```

Leave it off on servers behind split-horizon DNS where the local resolver returns private addresses for hosted domains.

## Tune the cache for mail workloads

The default Unbound cache is small. For a server handling more than a few thousand messages a day, raise the message and RRset caches and allow prefetching so popular records are refreshed before they expire. Put overrides in `/etc/unbound/conf.d/local.conf` rather than the CustomBuild-generated file:

```
server:
    msg-cache-size: 64m
    rrset-cache-size: 128m
    prefetch: yes
    num-threads: 2
    cache-min-ttl: 60
```

Restart Unbound and confirm the DNSBL lookups Exim performs now hit the cache by running the same query twice and watching the response time drop.

## HTTPS and SVCB records

Modern browsers use HTTPS records to learn that a site supports HTTP/2 or HTTP/3 and to obtain the Encrypted Client Hello configuration before the first connection. DirectAdmin’s DNS Administration and the user-level DNS page accept `HTTPS` and `SVCB` record types on current builds, and the templates can include a default entry for new zones. A minimal record that advertises HTTP/2 and HTTP/3 for a site served directly by the server looks like this in the zone:

```
example.com.    3600 IN HTTPS 1 . alpn="h2,h3"
www.example.com. 3600 IN HTTPS 1 . alpn="h2,h3"
```

Only advertise `h3` if the web server actually speaks QUIC; LiteSpeed does, Apache does not. Publishing `h3` on an Apache server causes some clients to attempt UDP first and wait for a timeout before falling back.

The record is added in the DNS manager by choosing the HTTPS type, entering the priority `1`, the target `.`, and the parameter string. To add it to the zone template for all new domains, edit `/usr/local/directadmin/data/templates/custom/dns_https.conf` following the same naming convention as the existing `dns_a.conf` and `dns_mx.conf` files, and check the changelog for the exact template name on your build.

## Common pitfall: DNSSEC validation breaking upstream lookups

Unbound validates DNSSEC by default. A domain with a broken DNSSEC chain returns SERVFAIL locally even though the provider’s resolver, which may not validate, answered fine. This surfaces as mail bouncing with a temporary DNS failure for one specific domain. Confirm with `dig +cd` against Unbound, which disables checking; if the answer appears, the remote domain’s DNSSEC is at fault and the correct action is to tell the recipient’s administrator, not to disable validation.

## Verify

Check the resolver chain and the new records:

```
dig +short @127.0.0.1 example.com A
unbound-control stats_noreset | grep -E 'total.num.cachehits|total.num.queries'
dig +short example.com HTTPS
dig +short @ns1.example.net example.com HTTPS
```

The cache-hit counter should climb steadily on a mail server. For the HTTPS record, compare the answer from a public resolver with the answer from your own nameserver; a mismatch means the zone was edited but not reloaded, which `rndc reload example.com` fixes. If the server is part of a DNS cluster, confirm the record was pushed to the peers as described in [Multi-server DNS clustering on DirectAdmin](/guides/directadmin-dns-clustering-multi-server/).

## DirectAdmin Unbound resolver at a glance

**Official documentation:** [CloudLinux documentation](https://docs.cloudlinux.com/), [DirectAdmin documentation](https://docs.directadmin.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Issuing wildcard certificates with DNS challenges on DirectAdmin](https://srvscripts.com/guides/directadmin-wildcard-certificate-dns/) · [DirectAdmin multi-server setup: DNS clustering and shared user/domain checks](https://srvscripts.com/guides/directadmin-dns-clustering-multi-server/) · [Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation](https://srvscripts.com/guides/directadmin-1-711-tls-privilege-escalation/).

## Frequently asked questions

### Does running Unbound on DirectAdmin interfere with BIND as the authoritative nameserver?

No, provided they listen on different addresses: Unbound on `127.0.0.1` and `::1` and BIND on the public IPs. The only conflict is when `named` also binds loopback, which the `listen-on` directive in `/etc/named.conf` resolves.

### How long does it take for Unbound to speed up mail scanning?

The benefit appears within minutes of Exim and Rspamd starting to query it, because DNSBL and SPF answers are cached after the first lookup; the cache-hit counter in `unbound-control stats` rises steadily on a busy mail server within the first hour.

### Can I undo this?

Yes. Restore the previous `nameserver` lines in `/etc/resolv.conf` (removing the immutable flag first), set `acme_use_only_system_resolver` back to `0`, then set `unbound no` in CustomBuild and stop the service; published HTTPS records are deleted from the DNS manager like any other record.
