01 Unbound를 재귀 해석기로 설치
Bind it to localhost on a non-standard port so AdGuard Home can take 53.
apt install -y unbound
cat >/etc/unbound/unbound.conf.d/local.conf <<'EOF'
server:
interface: 127.0.0.1@5335
do-ip6: yes
prefetch: yes
hide-identity: yes
hide-version: yes
qname-minimisation: yes
EOF
systemctl restart unbound 02 AdGuard Home 설치
The installer sets up a systemd unit and a web interface on port 3000 for initial configuration.
curl -sSL https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -v 03 AdGuard를 Unbound에 연결
In Settings → DNS, set the upstream to 127.0.0.1:5335 and disable all other upstreams. Full recursion means no third party sees your queries at all.
04 DNS-over-HTTPS 활성화
Get a certificate with Certbot, then enable DoH on 443 and DoT on 853 in the encryption settings. Clients then reach the resolver privately in transit as well as at rest.
certbot certonly --standalone -d dns.example.com 05 보안 강화
Restrict access by client IP, or require DoH with a secret path. An open resolver is recruited into DNS amplification attacks within days and will be null-routed.