dig
This what I setSystem , Settings, General - DNS servers blankDisable - Allow DNS server list to be overridden by DHCP/PPP on WANDisable - Do not use the local DNS service as a nameserver for this systemUnbound on LAN INT listening port 53LAN firewall rules , source internal vlans to destination (this firewall) port 53Unbound access lists allowing internal vlansUnbound - DNS over TLS8.8.8.8853dns.google.com1.1.1.1853cloudflare-dns.comClients DNS set to opnsense DNS. Or if internal DNS servers like domain controllers, client's DNS set to DC. DC forwards set to opnsense 53. Internal DNS unencrypted 53. External queries over TLS 853 to ones you specify.