In recursor mode IPFire is acting as the recursor dns server and contacting the individual name servers itself.
See this blog post for more info.
https://blog.ipfire.org/post/what-you-can-do-with-the-new-dns-features-in-ipfire
It could be that the strange IP’s you see are the names of name servers that IPFire is trying to contact. Why they are getting blocked I don’t know. Are you using the IP Blocklist. Could some of those IP’s be in an IP blocklist.
If you check the source of the IP’s do they resolve to a name server or to what?
For info recursor mode can not run in TLS mode so all the recursor mode traffic is in clear text.
https://community.ipfire.org/t/tls-in-recursor-mode/6005/9
As the first blog post says it is a trade off for the various options and you have to decide what makes best sense for your setup.