Configuring unbound to not forward certain requests but resolve those itself?

I am using postfix and unbound. In postfix I use DNSBL from zen.spamhaus.org.

My unbound uses cloud9 (9.9.9.9) as a standard forwarder, because 9.9.9.9 blocks a large number of bad actors.

But that means DNSBL from spamhaus doesn’t work because spamhaus DNSBL doesn’t allow DNS queries from public DNS resolvers such as cloud9. For spamhaus.org, I must go direct.

Is there a way to configure this just for spamhaus.org or does this mean my resolver must do everything without forwarding?

Thanks,

Gerben Wierda (LinkedIn)
R&A Enterprise Architecture (main site)
Book: Chess and the Art of Enterprise Architecture
Book: Mastering ArchiMate

Forget about this question, it was based on a misunderstanding of what was going wrong.

Gerben