Own or Public DNS resolver

  1. Use pfSense unbound, enable DNSSEC and SSL/TLS.
  2. Add FW rule to redirect all outbound DNS queries to local DNS server

  1. Run DNS spoofability test. GRC | DNS Nameserver Spoofability Test