First, disable DNSSEC validation for the bit. TLD. Namecoin doesn't support DNSSEC:
server: ... domain-insecure: "bit."
Then add the addresses of the public Namecoin resolvers to a forward-zone block for the bit. TLD:
forward-zone: name: "bit." forward-addr: 2001:41d0:2:a5d9::101 # French bit. DNS resolver forward-addr: 220.127.116.11 # French bit. DNS resolver forward-addr: 18.104.22.168 # German bit. DNS resolver
Reload Unbound to load the configuration changes.