There's no reason to move Unbound from 53. No need for system servers either, a couple DoT servers will suffice.A single port forward rule can take all DNS traffic and redirect it to AGH
You either choose your upstream servers or use the ones provided by the ISP. Unbound has no preset upstreams by default