Thank you jimp. On my question to them, Molotov TV confirmed to me that they cannot warrant anything if I do not use my ISP's DNS servers. Well: my chosen servers are cloudflare's and Quad9: nothing to do with my ISP.
So I used this setup two or three evenings with, on the pfSense firewall, formarding mode unchecked (off). I could watch TV through the Apple TV and Molotov, everything worked.
To be extra sure, I tried as a last attempt to check again forwarding mode, to return my setup exactly to what it was in the first place when my tests failed. Il should fail as it did before. But it now works beautifully. I double-checked and rebooted the firewall. Still works.
I feel like a fool with my silly questions. Maybe my little 127.0.0.1 DNS server knows it all and no longer need any assistance. Thank you for the reply. It helped a lot, and my Apple TV now works, hopefully with DNS over TLS using Cloudflare and Quad9's DNS servers.