This is a great writeup - and I'm really wanting to implement this.  I'm a full n00b with opnsense so bear with me.  I'm currently running unbound/bind.  I really like the filtering options in bind eg: force safe search etc. etc. with kids in the house.  That being said, it seems that if I want to use this method of DNS over TLS or something like DNSCrypt, I have to give up the filtering of bind?  Is there a way to keep it all?
				
			 "
"