This is OT but to finish, I'm talking about standard bypass. Going to QoS tab, Classification Tab, and entering 53 in the destination port shows I have three clients right now using alternative (unencrypted) DNS servers. I find that a security risk and would rather have my clients use my chosen server which is more secure (DoT). This is what I was using DNS Director to do in 3004. I will now have to use the global redirection but I'd rather be targetted to just those "misbehaving" clients.Tick "prevent client auto DoH" in the Wan section so that it doesn't bypass your global DNS.