Modern alternatives to BIND that I have had good (though limited) experience with:
- unbound (recursive resolver) https://www.unbound.net
- nsd (authoritative server) https://www.nlnetlabs.nl/projects/nsd
- unbound (recursive resolver) https://www.unbound.net
- nsd (authoritative server) https://www.nlnetlabs.nl/projects/nsd
This is what I do, which allows me the full gamut of BIND features without exposing those servers directly to any networks (there is a non-routed vlan that nsd/unbound/bind servers use). This is using split-horizon, DDNS from ISC DHCP and DNSSEC, so not a non-trivial setup, but it is also my home network setup so not so heavy duty as to be particularly hard to set up and automate.
I also have a round-robin DNSCRYPT setup hooked into the whole thing for semi-anonymity of queries.