Resurrected with a solution ;)
The key was, I realised after some sleep, that the commands only allowed traffic with destination IP/port 53. In the standard R9000 configuration, the block LAN/WLAN is both ways, so also rules need to be added for the source.
So, for both 5Ghz/2.4Ghz and TCP/UDP...