The key takeaway is what was posted in the solution.
In response to a case opened with support, the user received the following:
"Port forwarding, 1:1 NAT and 1:M NAT traffic are not inspected by layer 7 rules. So, any external traffic coming from one of the blocked countries will still be seen in your network; traffic will not go out to those countries though."
We can also see that the wording in the documentation was updated to reflect that it will only inspect return traffic from external, not externally sourced traffic hitting DNAT.
Original:
"The Layer 7 Firewall can also be used to block traffic based on the source country of inbound traffic or the destination country of outbound traffic. "
Now:
"The Layer 7 Firewall can be used to block traffic based on the destination country of outbound traffic and the source of return traffic"
This to me aligns and is quite clear, however if you require further clarification, as you mentioned you can open a support case to confirm.