> So unbound asks dnsmasq for the address
> of "myhost.lan" as it is instructed by forward-zone, gets correct result (!),
> but then marks it bogus because it cannot establish trust chain.
You'll need
private-domain: "lan."
domain-insecure: "lan."
Regards,
-JP