Could it possibly be some background check for valid domain names for proton pass? I imagine there could be a benefit to checking that the URLs associated with saved entries are actually live.
If the goal was exfiltrating a list of the sites you use, they don't really need to do it via some weird DNS stuff, since you're already expecting traffic directed at the proton api. They could just transfer an encrypted text file and call it a day. Doing this makes a ton of noise that you'd want to avoid if you were doing something shady, so it must serve some kind of function.

