Block it on the INPUT chain so that your DNS server is not accessed from the internet.
Your dns lookups work fine or you are having trouble resolving from your ISP’s DNS servers?
If you block it for output dns resolve won’t work, so leave it open.