he did a great job explaining the exact issue we're seeing and his resolution: to set his local-zone type to refused
Awesome. I think that's the route I'd rather go. Thanks again.
On a related note.....can anyone simply and clearly explain to me when and why Settings->General DNS servers are use by OPNsense vs the ones in Unbound? I mean, with Forwarding disabled and "Do not use the local DNS service as a nameserver for this system" both disabled? I'm trying to understand the use cases.