Overriding one name in a public domain without breaking the domain
A single internal zone for the domain makes the resolver authoritative for all of it, so mail and the public site start returning NXDOMAIN to everyone in the house.
A single internal zone for the domain makes the resolver authoritative for all of it, so mail and the public site start returning NXDOMAIN to everyone in the house.
An adlist with no group assignment applies to no client. Mine had 93,516 domains in it and had been doing nothing for as long as it had been there.
The UDM runs Debian and systemd, so it can run an nspawn container. What it cannot do is let that container talk to the router it is attached to.