Pi-hole + Unbound vs NextDNS on a Laptop: When You Leave Home and DNS Breaks
Benito Ruiz
September 18, 2026
At home, Pi-hole plus Unbound is the DNS I will defend. The Pi answers the LAN, Unbound walks the roots, I do not send every query to 1.1.1.1, and the blocklists are a file I can diff. On a laptop, that architecture is a destination, not a setting. The first hotel DHCP lease replaces it with 172.something, or it leaves a static 192.168.1.53 that no longer exists, and suddenly Slack is fine (app DoH) while git clone hangs (system resolver) and the captive portal never loads because I “hardened” DNS.
NextDNS is the product you buy when you admit the laptop leaves the house. Comparing it to Pi-hole plus Unbound as if they were two apps on the same machine misses the failure: one stack is a house, the other is a profile that follows a NIC.
What works on the couch
Pi-hole 6 (or 5, if you have not touched the box) as DHCP or as the DNS the router hands out. Unbound as the only upstream, recursive, DNSSEC, listening on 127.0.0.1#5335. Conditional forwards for lan or home.arpa so the printer still has a name. I like this because a query for some ad CDN dies on the Pi, and a query for a bank walks the chain without a third-party filter company seeing the name. Unbound will also fail closed if a network — a corporate guest, a locked-down travel Wi-Fi — will not let you talk to the roots. That closed failure is honest. It is also how you discover you cannot recurse from a train.
The laptop on the couch uses DHCP. It gets 192.168.1.53. Magic. I forget this is a location.

What breaks in a hotel
Static DNS on the laptop pointed at the house Pi. The hotel has no route to 192.168.1.53. Or it does, because someone else’s apartment uses the same prefix, and you are now sending queries to a stranger’s resolver. I have done the second one. The first is more common. Either way, “Pi-hole is down” is a laptop story, not a Pi story.
Tailscale split DNS pointed at the house Pi. This is the clever fix. ts.net and maybe . or a list of domains go to 100.x of the Pi. It works until the Mini PC is off, the Pi’s SD card is read-only again, or the hotel captive portal needs plaintext DNS to a local gateway before Tailscale is allowed out. I have sat in a lobby with a working tailnet and a browser that could not load the “click Accept” page because I had already forced DoH to the house.
Unbound on the laptop itself. I have run it. It is a nice experiment on Linux. On Windows it is a service I will not maintain. On macOS it is a brew service that dies after an upgrade. Recursion from a coffee shop also lights up a pattern some networks treat as malware. NextDNS over DoH looks like HTTPS. Walking roots looks like a scanner.
Firefox and Chrome DoH, iCloud Private Relay, Android Private DNS. The system resolver can be Pi-hole at home and the browser still talks to Cloudflare. On the road, the system resolver can be NextDNS and Safari still talks to Relay. I test with the app I am debugging, not with nslookup.
What NextDNS is actually selling
A resolver in their anycast, a profile, and clients that speak DoH/DoT/DoQ so a hotel cannot easily intercept the query. Blocklists you click instead of hostfiles you curate. Analytics you can turn down. A rewrite feature that is not as nice as Pi-hole’s local DNS records but works from a phone. An Apple configuration profile that survives the DHCP of a new SSID.
The trade is obvious and I will not dress it up. NextDNS sees the names, or sees enough of the SNI-shaped metadata that a filter company sees. You are not walking the roots. You are a customer of a resolver that has been good to me and is still not Unbound on my hardware. If that sentence bothers you more than a broken git clone on a trip, stay on the house Pi and accept the captive-portal pain. If it does not, NextDNS on the laptop and Pi-hole on the LAN is a split I run without shame.
NextDNS also has a “denylist” that will break the same banks and CDNs your Pi-hole lists break. The difference is you will debug it in their log from a phone, not in /var/log on a Pi you cannot reach because you did not turn Tailscale on before you left.
A laptop setup that survives both places
I do not point the laptop’s adapter at 192.168.1.53 anymore. At home, the router still hands the Pi to phones and IoT. The laptop uses NextDNS via the official app on Windows, or a device profile on macOS, with the same blocklists I care about, plus a rewrite for nas.home.arpa that I keep forgetting is stale when I change prefixes. For names that must stay in the house — Home Assistant, the Pi itself — I use Tailscale MagicDNS and *.ts.net, not a house search domain that dies on LTE.
When I need the house Pi’s exact lists on the road, I add the Pi as a Tailscale subnet or I run NextDNS’s linked IP only as a fallback, not as the only path. Linked IP is “their resolver knows my home egress.” It is not a laptop profile. Hotels will not have that IP.
Captive portals: I keep a network location or a one-click habit that disables encrypted DNS, accepts the portal, then turns it back on. NextDNS’s app has failed me here less often than a hard-coded Unbound. Pi-hole-over-Tailscale has failed me here more often than either, because the portal never gets a chance to be a portal.

IoT stays on the Pi
I do not put NextDNS on the ESPHome VLAN as the only resolver unless I am testing. Cheap devices want a plain DNS IP. Some of them ignore DHCP and hammer 8.8.8.8. Pi-hole plus a firewall redirect is the house tool for that. NextDNS on a router (some OpenWrt / GL.iNet packages) can do it for travel routers. For the apartment, the Pi still earns its electricity.
Unbound stays behind the Pi, not on the laptop. The recursive story is a property of a machine that never leaves. If I put Unbound on the laptop and a network blocks IP 53 to the world, I have a very private failure. NextDNS over 443 usually still works. That is not a moral win. It is a transport win.
When I still hairpin to the house
If I need a local record that NextDNS should not know — a lab name, an internal CA experiment — I keep it on Pi-hole and I resolve it only while Tailscale is up, via split DNS for that suffix only. I do not send . to the Pi from a hotel. Sending the root zone to a house resolver is how a laptop becomes unusable when the house is dark.
Arjun would talk about iPhone profiles here. On a laptop the same fight is: NextDNS app versus browser DoH versus OS encrypted DNS, only one of them is in the settings pane you opened. I disable browser DoH on the travel Firefox so the NextDNS app is the path I can see. I leave it enabled on the home desktop, which is how I confuse myself later.
Windows, macOS, and the resolver you did not click
On Windows, NextDNS’s app installs a service that wins more often than a NIC IPv4 DNS box I typed by hand. Group policy and a work VPN will still override it. I have had a corporate Pulse / GlobalProtect client replace DNS for the hour I was “on the tunnel,” then leave a leftover NRPT rule that sent . nowhere after I disconnected. Pi-hole cannot save you from that. NextDNS cannot either until you delete the leftover. Get-DnsClientNrptRule is the boring check I now run when a laptop “cannot see the internet” after a client meeting.
On macOS, a NextDNS profile and a manually set DNS on Wi-Fi are two sources of truth. Ventura and later also have encrypted DNS in a place I forget exists. I pick one. I do not stack a profile, a Wi-Fi DNS of 192.168.1.53, and Firefox DoH. That stack is how Slack works, Safari fails, and Terminal hangs on curl https://github.com.
Android Private DNS set to a NextDNS hostname is the cleanest phone story I have. The laptop is messier because we still treat Ethernet and Wi-Fi as two adapters with two memories. I name the home SSID’s DNS empty (DHCP) and I let NextDNS own the machine. The Pi remains the house’s DHCP answer for everything that is not this laptop.
Trade-offs I will not flatten
Pi-hole plus Unbound is the right house. It is the wrong exclusive laptop DNS. NextDNS is the right roaming profile. It is the wrong place to hide a homelab’s private names if you can avoid it. Tailscale-to-Pi is a third option that is excellent on a train with a working tailnet and miserable in a portal lobby.
I pay for NextDNS because the free tier’s log and query cap make me stingy about debugging. I still run Unbound because I like recursion when I am allowed to recurse. Those are not competing religions on the same NIC. They are two rooms. The laptop walks between them. DNS that cannot walk will look like “the internet is down” in the one room you are actually in.
If your only computer never leaves, skip NextDNS and keep the Pi honest. If your only computer always leaves, skip the fantasy that Unbound in the backpack will behave like Unbound in the closet. I have a closet. I still install the NextDNS app on the machine that goes through TSA.