Correct. We run it without it and just use the DNS filtering aspect.
How does it do DNS filtering without TLS interception - takeover for DNS resolution?
In what way are DNS resolution and TLS related except for the little-used DoT?