Later comment in hope that the tech info will be useful for anybody.
Related to no.4 I presume that there is an outside Lemmy hack to achieve this purpose. The container/VM that is hosting Lemmy should use a separate DNS server that can serve records only for the pre-defined list of internet domains and deny the rest.
Please mind that this is just a supposition, I did not test it !