Where Does Unbound Store Config and Keys?
Unbound resolver config and root trust anchor paths on Linux for validating DNS setups. With backup tips.
Last updated
Unbound keeps resolver settings in /etc/unbound/unbound.conf with forwarders, access control, and cache sizes. That file is the install to back up.
DNSSEC validation needs a root trust anchor beside it, usually root.key. The anchor updates with unbound-anchor on schedule. Back up the config folder with the anchor. Stale anchors break validation silently. Forward zones delegate domains. Access lists gate clients. Prefetch refreshes popular names. Local zones override upstream. Stats count cache hits.
Where Unbound stores this, by platform
/etc/unbound/unbound.conf
Forwarder, access, and cache settings for the resolver. Test with unbound-checkconf before reloading. Keep with the trust anchor.
/etc/unbound/root.key
DNSSEC root key for validation chains. Refresh with unbound-anchor on schedule. Copy with the config folder.
Frequently asked questions
what do i back up for an Unbound move
Copy /etc/unbound with root.key for full moves. The config holds forwarders and access rules. The anchor validates DNSSEC. Both restore resolution. Check version paths.
where is the Unbound trust anchor stored
Open unbound.conf in /etc/unbound to read server and zone blocks. Trust anchors default beside it as root.key. The file decides validation. Keep copies safe.
Notice an outdated path? Let us know.