If you used these instructions to setup dnsmasq, then dnsmasq would be configured with a different port (53035) than unbound (53). This way, only unbound is used for normal dns and other clients cannot access dnsmasq via 53053 unless you create a rule for it. The instructions also discuss reverse lookups which is basically done the way you have already configured.
Edit: link to instructions: https://docs.opnsense.org/manual/dnsmasq.html
Edit: link to instructions: https://docs.opnsense.org/manual/dnsmasq.html
"