This will take a few iterations.
My xarta.co.uk domain name is registered with 1and1.co.uk. I’ve set their name-servers to forward queries for xarta.co.uk to my free account on dyn.com. Eventually I want to set-up my own BIND (authoritative) DNS server at home, and skip dyn.com. pfSense uses BIND behind the scenes for Unbound which I use internally … but I want to keep Unbound limited to internal DNS for both security, and for flexibility e.g. split-dns. So meantime, on Dyn.com: