WOW!
I used the guide, Thank you so much!
You saved me few hundred bucks.
I try to use Unbound as resolver but I experienced some problems, so I switch it to work as Forwarder,
The AGH is listen to port 53, Unbound is listen to port 5353 then forward TLS queries to Cloudflare/Quad9/Google DNS...