Which service are you using? Quad9?
DNS Filter.
DNSFilter software delivers content filtering and website blocking solutions designed to enhance network security with protective DNS services.
www.dnsfilter.com
I started using Quad9 for all my clients years ago, such as, for "forwarders" for the DNS service on their domain controller. Or if just a workgroup, for their routers DNS forwarding. But, to the best of my knowledge, Quad9 does not have any "paid for service" that you can customize, get granular with, or utilize agents with. I focus on the "Pro" agent.
It's similar to Cisco Umbrella. ...which I'd never touch...cuz it's..Cisco.
For larger clients with a DC, you can spin up a virtual guest instance of a *nix powered DNS service...customizable to it can split the local AD requests, and the public side requests. And get deeper reporting than if you just leverage the DNS forwarders on the DC.
And the best approach, agents on each/every computer.
I also looked at Zorus, which was started by a couple of people from Datto. But...it's too pricey, and isn't as flexible.
IMO, UTM's are losing their advantage. Well over 50% of LAN/WAN and visa versa traffic is httpS/SSL now. Even malware! So...they won't sniff it. Yeah, there's SSL inspection which I've setup on a few clients, but it's not easy to deploy anymore and just isn't practical anymore..and getting worse. Handling stuff at the DNS/IP level with agents like this, esp with portable computers...it's the way to go lately.