Considering that built-in "Private DNS" (actually DoTLS over port 853/tcp) has become an opt-out feature among numerous vendors by default, the non-VPN section may require additional steps remarking on either settling for that or disabling for the sake of using Nebulo. Not addressing this leads to suggested configuration never matching on DNS traffic, as it is never sent over 53/udp.
Considering that built-in "Private DNS" (actually DoTLS over port 853/tcp) has become an opt-out feature among numerous vendors by default, the non-VPN section may require additional steps remarking on either settling for that or disabling for the sake of using Nebulo. Not addressing this leads to suggested configuration never matching on DNS traffic, as it is never sent over 53/udp.