To avoid hitting the root, don't send your queries there! Problem solved!
localroot.isi.edu
Bias: I created it, and am a author of one potential set of future specifications (rewrite).
localroot.isi.edu
Bias: I created it, and am a author of one potential set of future specifications (rewrite).
What is the primary difference between using an Unbound auth-zone (as described in the RFC) compared to localroot?
Both methods are fine. It would be best if unbound does ZONEMD checking to ensure the file you receive is properly protected from modification from any network in the middle, and I don't remember without looking what version (and if) Unbound does this. If they don't yet, it's coming soon. With the LocalRoot service at ISI, the TSIG protection gives you this (and is older than the ZONEMD record that is now available in the root zone).