@johnpoz That's great JP.

Yes the dig command certainly returns a good visual of what's going on under the bonnet :)

I will never look at DNS requests the same way again!

And I am sold on the concept of having pfsense in Resolver Mode rather than Forwarding Mode...