I have had those for a while as well. I believe they are pi-hole itself, using IPV6 internally, to resolve DS and DNSKEY queries. I have IPV6 disabled, via net.ipv6.conf options but pi-hole still listens on tcp6 0 0 [::]:domain [::]:* LISTEN apparently and can respond to its own queries. I haven't found any decent way of disabling the IPV6 stack other than a kernel option nor have I found a way to enter a hosts entry for the 'all zero' IPV6 address.