When I set up an IoT device on a different subnet, it inherited my phone's DNS setting. So the device was trying to use the pihole but it was 2 hops away, triggering the alert.
I still think having the IP address printed by default is a good idea -- if I had been I would seen immediately what was causing the warning and wouldn't have had to bother you here.