Do you have the option to resolve only DNS names from System>Network>Overview enabled on the role?
Do you see the DNS request going out the WSAM interface?
Do you see the DNS request on a TCP dump on the internal port?
Do you have a proxy configured in the browser?
What does the user access log say in relation to the request?
If you open the WSAM icon & open to the advanced view & look at the logging tab, do you see the connection/lookup succeed?