Ok, so for clarity:

  1. WG clients get the 192.168.8.1 setting pushed.
  2. WG clients can execute LAN DNS queries but cannot execute other DNS queries OR
  3. WG clients can’t execute any DNS queries, including LAN queries?

If 2), it seems like some sort of dnsmasq problem. If 3, it might be some sort of firewall/interface issue.

Are you able to use dig on a WG client for output?