@stephenw10 Good point. Should have explained. Apologies.
The filter I applied was by IP. All 192.168.199.x devices belong to VLAN99.
And there is only one rule that allows outbound traffic from that VLAN and that is the rule we are discussing here.
There are a couple of states to the DNS server which is commanded by an interface group rule and that seems to have some traffic Ok based on the above screenshot.
Interestingly when I filter by rule Id, I don't get any results.