I believe you can still block the specific destination IPs with pf using murus if you want, but yes it's quite bothersome.
You can find the full list of apps that bypass it here:
/System/Library/Frameworks/NetworkExtension.framework/Versions/A/Resources/Info.plist under ContentFilterExclusionList.
https://twitter.com/patrickwardle/status/1318437929497235457