After upgrade to 2.3 I have to uncheck Enable DNSSEC Support in DNS resolver to avoid a SERVFAIL. It may be coincidence because it is the same in 2.2.6. Any ideas?
unbound: [99597:0] info: failed to prime trust anchor – DNSKEY rrset is not secure . DNSKEY IN