[solved] best practice with unbound in pfSense and email-server behind it?
-
Just to recap, I couldn't use Unbound in resolver-mode for those mx because sites like zen.spamhaus.org wouldn't work with it, I don't know the reason.
Also I couldn't disable rebind protection because split-DNS wouldn't work anymore when I was using my domain with DNSSEC.
So I have to use a third party DNS-server for those mx which is not blocked by spamhaus.org and alike. And because I still have a need for some split-DNS like behavior for my mx, I made a port forward from one external to one internal address in pfSense to cope with that.
And it is running smoothly now. But it is more complicated than I had imagined.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.