IPv6 wasn't static and therefore the pi-hole could be bypassed; fixed this with the NetworkManager by setting the IPv6 of pi static and then using this as preferred dns server in router
I am running a second router as repeater to fully cover my flat (very thick brick walls...), which wasn't set to Access Point mode and therefore also handed out own IP adresses; fixed it by setting the router to access point mode
I hope this might help someone who is running into the same issues.
Do you have any recommendations on how to do this better?
Just for context, I'm using a Speedport as the main router, and I've read on different pages that it may cause additional trouble and does not offer many customization options.