Run two and check the logs. You'll see about 20% of your requests will log on the second instance. So currently, that's 20% of your DNS requests not being filtered.
You'll also find some devices just latch on the the second and never use the first - again, in your scenario, these are not being filtered.