Try to cut the line in 2 pipes of 500Mbps each.
Assign HTTPS, DNS and VoIP on 1 pipe and enable QoS on it.
Assign everything else on the other pipe without any QoS.
I hope your CPU can handle this approach.
This is a malware domain, blocked by Mastercard.
Use dig command to see which dns providers actually block this malicious domain. (OpenDNS free plan does not block it, while Cisco Umbrella paid tier, blocks it as malware)
For example
dig a4p.adpartner.pro @9.9.9.9
We are out of topic, but since we are talking about dns, I would post my thoughts:
Cisco Umbrella/Opendns:
+Spend the most money on dns infrastructure than anyone else
+Don't add any experimental features
-Have no malware blocking on the free tier.
Google DNS:
+Many locations and good...
You can set Domain Overrides on Unbound, so you will use other dns servers for these domains that get blocked.
I'm saying this because you may face blocks using other dns services too.