knot-resolver: use the policy hack consistently
Doing this differently for ISP's servers than others seemed really ugly (probably unintentional mistake). Now we only put RPZ into policy.rules which is probably OK; certainly not as bad as this.
I tested it by applying manually onto a running HBT. I think it should also help some cases of "slow luci" – I suspect this difference might be the main reason why switching to forwarding helped some people.