It's a general feature of consumer routers to filter DNS responses of external servers that point to internal addresses. There are attack techniques that use this.
I am not familiar with OPNsense and unbound in this regard, because I am running BIND.