will try before asking any more questions :)
host is running unbound dns daemon lsof verifies localhost:domain bind. guest nflags from nattribute --get are 'lock.lback_remap,lback_allow,hide_netif,hide_lback,state_admin'. guest starts pdns (powerdns) daemon and reports "binding UDP socket to '0.0.0.0' port 53: Address already in use"
argh my bad. unfamiliar with pdns syntax. sorry. :) looks like it's working.