@PhoneBoy perhaps this would work, if CHeck Point is the one blocking it.
When I've added KnowBe4 domains to the categorization exceptions, the problems persisted, so in my case this was the issue:
When querying the https.protected-forms.com from inside the network, I was getting "can't find" in nslookup:

Looking in Check Point for this query, we see that it detects it as the query for malicious domain, but it allows it:

Finally, looking at the public DNS resolver that the Domain Controller forwarding the queries to, (IBM's Secure DNS Service Quad 9):

I have reached out to KnowBe4 and they are working on whitelisting this domain with threat intelligence providers.