I started to suspect that both my Apple TV and Homepod Mini were being naughty children making DNS queries to servers other than my local one.
So put together a list of the bigger public IPv4 and IPv6 DNS servers, then added a firewall rule rejecting all traffic to them from all devices other than my AdGuard Home server.
And guess what I found - I was right. Unauthorised communication with Cloudflare, and avoiding my AdGuard Home server.











