I do not block these requests. However I am pretty sure Apple does some DNS tunneling.
Also, some iOS specific requests happen when there is no other DNS activity at all.
Also, some iOS specific requests happen when there is no other DNS activity at all.
That seems very reasonable. It would be better than hardcoding IP addresses and safer than straight DNS for management things. Maybe their implementation of that doesn't have a very long TTL?