Firewall and alerts. I'm doing something wrong?


I have this issue witch I recently discovered: in F-Secure Policy Manager in Alerts tab my PC is showing "Warning: A DNS query was blocked for a domain." and every minute it gets new worning. DNS: It look familiar to me so I checked that I have firewall rule with this adres as remote host to block.

My furter investigeting show that when I swith rule off, no warning apears. And I also check in Wireshark that when rule is off there is no request for this DNS.

I'm not specialist in this topic so my question is: if the rule is on, F-Secure is looking for IP of this domain and then triggers Alert?