In https://unbound.docs.nlnetlabs.nl/en/latest/reference/rfc-compliance.html you indicate compliance with RFC 2181, which forbids NS records to point to CNAME records:
> 10.3. MX and NS records > The domain name used as the value of a NS resource record, or part of the > value of a MX resource record must not be an alias. But Unbound is currently supporting NS records pointing to CNAME records, following them in the regular way. Is this by design or is it a bug? For reference, BIND9 generates a SERVFAIL in such cases (https://groups.google.com/g/comp.protocols.dns.bind/c/MGJHdh7TSS4).
