@GLrs
No, I excluded both: .8.0/24 and .1.0/24
As you can see from dig @192.168.1.111 - all works even if kill switch is on

Remember: same config on GL-MT300N-V2 works fine.

but DNS forwarder on the router itself is not working when kill switch is on (see SERVFAIL in dig command)