If DNScrypt is a must, use the latest version in a docker container. The one in OPNsense is quite old, unsure where the issue is there but I wouldn't use it on the internet until it is upgraded to current.Bind -- zone management on the FW wouldn't be my first choice.For anything else Unbound is more than fit for the job, and latest version as well.Removing one or two if possible from the chain would help you narrow down the DNS issues.