Strange indeed :
[2.4.3-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: dig @192.168.1.1 google.co.uk
; <<>> DiG 9.11.2-P1 <<>> @192.168.1.1 google.co.uk
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60086
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;google.co.uk. IN A
;; ANSWER SECTION:
google.co.uk. 300 IN A 216.58.212.131
;; Query time: 167 msec
;; SERVER: 192.168.1.1#53(192.168.1.1)
;; WHEN: Mon Aug 20 07:32:50 CEST 2018
;; MSG SIZE rcvd: 57
Btw : I have "Harden DNSSEC Data" checked
The Resolver is working in resolver mode, right (no forwarding) ?
edit : stupid me, answered to your initial post - didn't saw the follow up, that completely solved the "issue" already.