VDS is used only because my ISP does not want to change PTR record for my static IPv4 address, that is required for outbound SMTP. Also it acts as a slave DNS server and DNS cache, just to make yet another round-robin hop for more privacy. All DNS-related traffic goes through transport IPsec tunnel. CPU | amd64 RAM | 1GB HDD | 10 GB NIC | 1Gbps => FreeBSD 13.2 amd64 OS => OpenSSH: remote login server, built without OpenSSL => NSD: DNS authoritative slave server => CurveDNS: DNSCurve server => Unbound: recursive cache => dqcache: recursive cache with DNSCurve => chrony: NTP server => Postfix: MTA => godlighty: HTTP and CGI server