exchange of information with restricted addresses - firewall flows

My CIS Premium has a global firewall rule that prohibits some IP4 addresses. But Windows 10 services like svchosts.ehe […] still exchange information with such forbidden address in the amount of tens of kilobytes. Is there something I can do about it?

Make sure the global rule is above any allowed rules and make sure the rule is set to outgoing and the IP4 address is only defined as the destination address.

Thanks for the answer.
Now all the rules look like this

action block
protocol TCP or UDP
Direction Outgoing and Incoming
Type Single IPv4 address
Departure address
Destination address any address

I assumed this forbids any exchange with the address
I was wrong?

Set the destination address to the IP address you want to block and leave the source/departure address to any.