A privacy-focused, validating, recursive, caching DNS resolver Docker image based on NLnet Labs Unbound.
amd64, arm64, and arm/v7version: '3'
services:
unbound:
image: bigbeartechworld/big-bear-unbound:latest
container_name: unbound
ports:
- "53:53/udp"
- "53:53/tcp"
volumes:
# Optional: Mount custom config
- ./unbound.conf:/etc/unbound/unbound.conf:ro
restart: unless-stopped
# Optional: Use host networking for better performance
# network_mode: host
docker run -d \
--name unbound \
-p 53:53/udp \
-p 53:53/tcp \
--restart unless-stopped \
bigbeartechworld/big-bear-unbound:latest
# Test DNS resolution
dig example.com @localhost
# Test DNSSEC validation
dig +dnssec nlnetlabs.nl @localhost
# Verify DNSSEC is working (should show "ad" flag for authenticated data)
dig +dnssec +short example.com @localhost
Mount your own unbound.conf to override the default configuration:
volumes:
- /path/to/your/unbound.conf:/etc/unbound/unbound.conf:ro
The default configuration includes:
| Option | Default | Description |
|---|---|---|
qname-minimisation | yes | Privacy: Sends minimal query info |
aggressive-nsec | yes | Performance: Reduces queries using NSEC |
prefetch | yes | Performance: Pre-fetches expiring entries |
serve-expired | yes | Reliability: Serves stale data while refreshing |
harden-* | yes | Security: Various hardening options |
cache-min-ttl | 300 | Cache minimum 5 minutes |
cache-max-ttl | 86400 | Cache maximum 24 hours |
To use DNS-over-TLS forwarding instead of recursive resolution, uncomment the forward-zone section in unbound.conf:
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 1.1.1.1@853#cloudflare-dns.com
forward-addr: 1.0.0.1@853#cloudflare-dns.com
For CasaOS users, use this docker-compose configuration:
version: '3'
services:
unbound:
image: bigbeartechworld/big-bear-unbound:latest
container_name: big-bear-unbound
ports:
- "5353:53/udp"
- "5353:53/tcp"
volumes:
- /DATA/AppData/big-bear-unbound/conf:/etc/unbound:ro
restart: unless-stopped
Note: Using port 5353 to avoid conflict with system DNS. Configure your devices to use port 5353 or set up port forwarding.
Use Unbound as upstream DNS for Pi-hole:
# In Pi-hole, set custom upstream DNS:
# Use the Docker network IP of your Unbound container, e.g.:
172.17.0.2#53
access-control in production.unbound user, not rootdocker logs unbound
docker exec unbound unbound-checkconf /etc/unbound/unbound.conf
Port 53 already in use: Stop systemd-resolved or use a different port
sudo systemctl stop systemd-resolved
Permission denied: Ensure mounted volumes are readable by UID 101 (unbound user)
DNSSEC failures: Check if your system clock is accurate
This Docker image configuration is provided under the MIT License. Unbound itself is licensed under the BSD License.
Content type
Image
Digest
sha256:9bf13bb06…
Size
57.6 MB
Last updated
12 days ago
docker pull bigbeartechworld/big-bear-unbound