I'm still trying to resolve this issue, but I have a few updates.
After running many packet captures at different points, and different VLAN configurations, we've found the following:
When the IAP is set to vlan 908, and the switch interface it connects to is vlan 908, we are able to resolve DNS.
When the IAP is set to VLAN 2521, broadcasting ssid 908, and the switch interface is set to native vlan2521(untagged) and 908 tagged, we are not able to resolve DNS. When running packet captures at the access switches uplink, we are able to see the DNS response packets arrive at the switch, but no discards or errors occur at the IAP interface on the switch. The switch has routing disabled, so it is not making any decisions. If we tag vlan 1100 ontop of this, that SSID is able to recieve DNS.
Aruba support has been assisting us for the past 2 weeks on this, and are having great difficulty in figuring out why this is occuring, so I want to reach out to more sources of help with Airheads.