@johnpoz said in Unbound not resolving delegated NS record:
He has a delegated sub to a NS on his internal network and he wants outside and inside to resolve this? Is that the actual problem? Is this internal NS running unbound - if so that is wrong choice, unbound is not meant to be an authoritative NS.. etc..
There are many reasons, other than the reason you have concern about, why you might want to delegate a NS to another nameserver. What it serves (private vs external IP) isn't really the point of the question. That nameserver is running on a machine behind a firewall/NAT, and so pfSense's job is to forward the DNS request to the DNS server.
This works for external DNS servers to look up IPs, but doesn't work for pfSense or anything that uses the pfSense DNS server without overriding the host of the internal nameserver manually for each domain this happens on.