Getting DNSMASQ_WARN "Negative DS reply without NS record received for nas, assuming non-DNSSEC domain-specific server." The installation is fresh on raspian trixie with unbound as recursive resolver and activated dnssec. Is this warning new, since i was a long time away from pihole?
Disable DNSSEC on Pi-hole.
If you have Unbound for upstream, it does already do DNSSEC validation for the public domains ... if available.
Dont need Pi-hole to do it a second time.
EDIT: Ps. the official Unbound guide also doesnt mention enabling DNSSEC on Pi-hole!