Closed mibere closed 4 years ago
I don't think this is a good idea. While having a dedicated, internal authoritative server and using split horizon is a good practice, it's not a requirement either, and such a change will break valid setups.
My own zones contain both private and public IPs, so that I can use any resolvers, both from the internal network and from a VPN.
People who really want to block this can do it in dnscrypt-proxy
with the IP filter, but doing it on the resolver itself doesn't seem like a good idea.
Feel free to close it if there is nothing to do :)
Is it necessary or a good idea to add this to unbound.conf?