VPN client DNS overreach

If ADG is enabled, all DNSs are handled by ADG, including the excluded domains set on VPN policy (that list is not related to ADG).

he excluded domain are just go to WAN port instead of using the VPN port when establishing TCP/HTTP. But the DNS queries will go to the VPN port.

You mentioned that the VPN provider you are using is Mullvad.
According to our experience, Mullvad will hijack all DNS (port 53) traffic, no matter what DNS server you set up in VPN profile, router DNS, ADG DNS, clients network adapter DNS, their DNS (port 53) after arriving at Mullvad VPN server, it will be resolved by Mullvad DNS.

(Small test: The Surfshark also do so, but NordVPN won't.)

As for limiting traffic or speed, it should be related to the application server, web server, etc. , not our router interface.