Just out of curiosity. Why do you want to filter DNS requests outside your IPFire system? The Mullvad DNS services seem to be just DNS resolvers, as unbound inside IPFire, with DNS filtering using RPZ mechanism ( @jon 's addon in progress does the same inside IPFire).