so it would be like you say I want Firefox to go thru the tunnel, you would want the DNS requests made from it to go thru as well, in this case they weren't tunneled and were just going to the normal dns server
not sure your exact case, but I would highly recommend using pipewire, Bluetooth audio devices were nothing but pain for me with pulse audio and they just worked on pipewire
lsof is a good tool would recommend it whenever something weird is happen, tho you gotta be root for it