Hi, the best option for redirecting DNS is to use rdr on the same interface.
rdr pass in quick on $if_lan proto { udp tcp } from any to any port domain -> lo0 port domain
I use it on OpenBSD
pass in quick on $if_lan proto { udp tcp } from any to any port domain rdr-to lo0 port domain
rdr pass in quick on $if_lan proto { udp tcp } from any to any port domain -> lo0 port domain
I use it on OpenBSD
pass in quick on $if_lan proto { udp tcp } from any to any port domain rdr-to lo0 port domain
"