Linux

Where Does Unbound Store Config and Keys?

Unbound resolver config and root trust anchor paths on Linux for validating DNS setups. With backup tips.

Last updated

Unbound keeps resolver settings in /etc/unbound/unbound.conf with forwarders, access control, and cache sizes. That file is the install to back up.

DNSSEC validation needs a root trust anchor beside it, usually root.key. The anchor updates with unbound-anchor on schedule. Back up the config folder with the anchor. Stale anchors break validation silently. Forward zones delegate domains. Access lists gate clients. Prefetch refreshes popular names. Local zones override upstream. Stats count cache hits.

Where Unbound stores this, by platform

Linux
/etc/unbound/unbound.conf

Forwarder, access, and cache settings for the resolver. Test with unbound-checkconf before reloading. Keep with the trust anchor.

Linux
/etc/unbound/root.key

DNSSEC root key for validation chains. Refresh with unbound-anchor on schedule. Copy with the config folder.

Frequently asked questions

what do i back up for an Unbound move

Copy /etc/unbound with root.key for full moves. The config holds forwarders and access rules. The anchor validates DNSSEC. Both restore resolution. Check version paths.

where is the Unbound trust anchor stored

Open unbound.conf in /etc/unbound to read server and zone blocks. Trust anchors default beside it as root.key. The file decides validation. Keep copies safe.

Notice an outdated path? Let us know.