{
  "slug": "unbound",
  "category": "dns-resolvers",
  "name": "Unbound",
  "description": "Validating, recursive and caching DNS resolver from NLnet Labs for running your own resolver, with DNS over TLS and DNS over HTTPS support.",
  "website": "https://nlnetlabs.nl/projects/unbound/about/",
  "source": "https://github.com/NLnetLabs/unbound",
  "license": "BSD-3-Clause",
  "platforms": [],
  "jurisdiction": {
    "code": "NL",
    "name": "Netherlands",
    "eyes": "Nine Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 85,
  "coverage": 100,
  "summary": "Unbound scores 85 out of 100 (grade B) on the DNS resolvers criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, Encrypted DNS and DNSSEC validation. It partly meets independent audit and no query logs. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/dns-resolvers/unbound/",
  "markdown": "https://privacyratings.com/dns-resolvers/unbound/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/NLnetLabs/unbound/blob/master/LICENSE",
      "note": "BSD-3-Clause."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/NLnetLabs/unbound",
      "note": "No telemetry or analytics in the source code."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://nlnetlabs.nl/about/",
      "note": "Developed by a non-profit foundation funded by donations and support contracts. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://ostif.org/wp-content/uploads/2019/12/X41-Unbound-Security-Audit-2019-Final-Report.pdf",
      "note": "The full X41 D-Sec audit report is older than three years."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "encrypted_dns": {
      "title": "Encrypted DNS",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://nlnetlabs.nl/projects/unbound/about/",
      "note": "DNS over TLS and DNS over HTTPS are supported."
    },
    "no_query_logs": {
      "title": "No query logs",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound.conf.html",
      "note": "Query logging is off by default and controlled by whoever runs the resolver. Not audited."
    },
    "dnssec_validation": {
      "title": "DNSSEC validation",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://nlnetlabs.nl/projects/unbound/about/",
      "note": "Unbound is a validating resolver."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:26.412Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}