That is because not every DNS request uses port 53... There is also DoT and DoH. Maybe this will explain it: https://forum.opnsense.org/index.php?topic=30066.msg145295#msg145295
igb0: WANigb1 - igb7: LAN (bridge called "Switch")
Interface: Switch (info see above)Proto: TCP/UDPSource Address: *Source Ports: *Destination Address: !RFC1918Destination Port: 53NAT IP: OPNsense (Alias with the OPNsense's IPv4 + IPv6 of "Switch" bridge)NAT Ports: 53
Protocol: IPv4+IPv6 TCP/UDPSource IP: *Source Port: *Destination: OPNsense (Alias explained above)Destination Port: 53
RFC1918 is an alias? What does it contain? Try out setting "!This Firewall"
192.168.0.0/1610.0.0.0/8172.16.0.0/12100.64.0.0/10127.0.0.0/8
Yes. I thought it's self-explanatory.