The DNS resolution fails over the connect tunnel client or from the AMC lookup feature
DNS query sent from the SMA device adds the addition EDNS header and this change was made from February 2019 after the DNS flag day update.
After February 1st 2019 major public DNS resolver operators will disable/stop accommodating work around for standards non-compliance responses and will start accepting DNS packets with EDNS extensions under the additional records
DNS packages on the SonicWall SMA devices have been updated to accommodate DNS requests with the additional resource records and this change was mainly for the GTO services. This ensures that the SMA appliances under GTO service remain responsive to EDNS queries.
This also affected any query made to the internal DNS server, as an appliance on 12.3 or 12.4 sends a DNS query with additional records to the internal DNS server. If the internal server is not capable of handling DNS packets with additional records, it responds back with a "format error".

Below image is the request from SMA appliance to the DNS server,

Windows server 2008 or 2012 might not handle DNS requests with EDNS records and DNS cookies, this is because EDNS or DNSSEC might note be enabled on the server.

Steps to fix this issue, Run the below command on windows server and enable DNSSEC on the DNS management properties,
--> dnscmd /config/enableednsprobes 1

For more details about DNS flag day, please refer the below link