RPZ Policy Test
Simulate a DNS resolution against a profile. The check evaluates allow/deny rules first (allow wins), then reports any blocklists that would otherwise apply.
This is a static evaluation of profile rules. Real blocklist hits are decided at resolve time by the SecDNS resolver + RPZ engine; this simulator reports which categories could block.