How do you know this to be the case? The domain could be in your gravity list.
In this case, which key word did you add as a regex (and how does it appear in
/etc/pihole/regex.list ), and what does the query log show for this lookup?
The query log will tell you if the query was blocked by gravity or by regex.
Example - I made a wildcard blacklist entry for “ru.com”. Then I ran
dig dog.ru.com and the reply is 0.0.0.0 from Pi-Hole (it was blocked). The query log shows the following:
With regex debugging mode on, this query shows in /var/log/pihole-FTL.log as follows, showing me again that the blocking was done by this regex filter.
[2019-02-11 12:03:21.846] DEBUG: Regex in line 3 "(^|\.)ru\.com$" matches "dog.ru.com"