Had to push firewall policy today stating that mask.apple-dns.net is NOT spyware, and to exclude that domain from the threat logs and to NOT drop that traffic.

:(

@kajer Why not? Just another DoH provider. Block or mitm (if they're not checking certs that's their problem).