@b0sman can you query anything from your vpn client to your 10.0.0.11?
say pfsense own name? When you add a vpn tunnel network.. I don't believe that adding a vpn tunnel network adds that to the unbound default ACLs
Also if you setup some domain override to go lookup this pc01.mydomain.local, that would be rebind if the answer is a rfc1918 IP.
Also .local is not a good choice for local tld, since .local is used by mdns.. I would suggest moving to better choice, either use home.arpa locally, or the new one is .internal