@johnpoz That's great JP. Yes the dig command certainly returns a good visual of what's going on under the bonnet :) I will never look at DNS requests the same way again! And I am sold on the concept of having pfsense in Resolver Mode rather than Forwarding Mode...