The allow action on domain EDLs has no effect on DNS Security
inspection. If a domain matches both an EDL configured with allow and a DNS Security
category, the DNS Security action is still applied. To actively exempt trusted domains
from inspection, use the bypass action.