The same config as me, in forwarders in dc dns i only have the opnsense ip. Then all go throught opnsense firewall.
I had that setup at home for some time. Except I used Pi-hole as DNS Forwarders which used DNS Root Hints.Your DC'd do not direct traffic, that is what OPNsense does for you with NAT ;-)