Some lists in the blocklist section will even lock Microsoft updates, seems like you're in that situation.If that's not the case your upstream DNS is doing something weird, and you should consider encrypting all your queries outbound
Can you post a screenshot of your DNSBL page with advanced turned on and one of the Unbound reporting screen?
Are you using blocklists? If you do there most probably is no "issue". Microsoft domains frequently end up on blocklists, all the more so if you pull in a lot of them managed by volunteers.Disable all block lists. Working now? If yes, then it's one of the blocklists, none of which are managed by the OPNsense project and none of which can be fixed by the OPNsense project.If no, then we have an issue.
ONLY use if you know what you doBe aware that these rules can also block Windows Update and other services.Therefore, no support will be provided on them.
Still not clear which lists are enabled at all, but there are some blocklists built in that explicitely blocks microsoft stuff:WindowsSpyBlocker (spy)WindowsSpyBlocker (update)WindowsSpyBlocker (extra)