I'm very glad to have learned more about Unbound this weekend as a result of your research and testing. I think it's a good DNS solution. But I still do not see the purpose to insert Unbound between dnsmasq and Stubby since Unbound will not perform its own recursive queries when a forward-zone is configured. Since it behaves as another forwarder to the Stubby upstream servers, it would make more sense to me to see:
Thanks again @rgnldo for all the work you've done teaching us how to integrate Unbound!
- dnsmasq with Stubby to an external recursive resolver (e.g. CloudFlare, Google, Quad9, etc.)
- dnsmasq with Unbound configured for DoT to an external recursive resolver
- Unbound without dnsmasq or Stubby without any forward-zones (unencrypted)
Thanks again @rgnldo for all the work you've done teaching us how to integrate Unbound!