exactly my setup.I can forward to DNS servers that are in my LAN or accessible via VPN... No leakage of sensitive information there.
Seems ok... Try it and see if it works
Maybe you need also routes defined for your gateways...
something like:
dst-host=*.yourdomain.com