Sophos DNS Protection and normal router

Hello,

I'm trying to get SophosDNS Protection up and running at a small office location.

There's just a regular router at the location.

I added the location, set up DNS forwarding to the Sophos DNS server and created a policy.

The dashboard shows DNS queries, but on the endpoints I can even reach addresses that should be blocked by the policy.

Where am I misunderstanding?

Thanks, Sebastian