View attachment 49479
It shows it has been Verified with DNSSEC in Query log.
View attachment 49478
It shows it is responding from cache with the RRSIG data intact.
Last, Your website works!
View attachment 49477
It sounds to me you are running into a problem where there is an issue between unbound+dnssec and adguardhome+dnssec. Unbound does a deep verification that sometimes does not behave when using dnssec on a pihole or an AdGuardHome. It is typically because Unbound strips away (or randomizes) too much information from the query response before it is sent to the client ( in your case, to adguardhome). Then AdGuardHome attempts to do the verification again, however there is too much info removed already. For example, in the pihole +unbound guide these are the only options adjusted for DNSSEC between unbound and pihole
Code:
# Trust glue only if it is within the server's authority
harden-glue: yes
# Require DNSSEC data for trust-anchored zones, if such data is absent, the zone becomes BOGUS
harden-dnssec-stripped: yes
# Don't use Capitalization randomization as it known to cause DNSSEC issues sometimes
# see https://discourse.pi-hole.net/t/unbound-stubby-or-dnscrypt-proxy/9378 for further details
use-caps-for-id: no