Try NSD. Unlike unbound, NSD is the actual authoritative name server in the project.
Its easy to feed an RBL to unbound to do pi-hole type work, I use pf to transparently redirect all external DNS requests to my local unbound server but I get the bind automation around things like DNSSEC, DHCP ddns and ACME cert renewals.
I'm surprised this isn't a more common stack.