Better (from a privacy and security aspect) would be running unbound on the router (in addition to the WG server), so that your router is your network's (and remote devices') own DNS resolver, with cache-miss queries going to Authoritative servers (the same ones that CloudFlare gets its info from, BTW). These Auth servers are even starting to implement DoT too, and IPSec and DNSSEC work very well (and I want to say especially on an IPv6 connection, with each device's IP address (with the v6 privacy settings correctly applied by you) in the galactically IMMENSE v6 address space, where it would be like trying to find a particular grain of sand in the metaphorical Saharan sand storm of the internet - easier than a WG client tunnel to a service you seem to trust), but again, you need to clarify your use case and threat model to find a "best fit" solution for you., I just set up my RT-AC86U with Warp+ from CloudFlare and thought I'd share how in case anyone else is interested. This is only for RT-AC86U (and RT-AX88U I assume though haven't tested) since it relies on the experimental WireGuard posted by @Odkrys. Here are the setup instructions: Sign up for, I'm trying to install Cloudflare Warp on my Ubuntu 23.04, but it seems that the official Cloudflare repository only provides support for LTS versions. Consequently, I'm unable to find a straightfor.