Hi
Goal of DST is to redirect traffic from certain domains directly through the client internet connection and avoid tunneling it toward the asa.
Your remote clients have a proxy configured? Is it cloud or private?
So if you're using a private proxy, these domains have to removed otherwise they'll still go through the proxy which means through the vpn.
If that's a cloud service, then don't need to remove them because you can keep the traffic to go through your cloud proxy and not tunnel them back to your asa to then go to your cloud proxy.
Is that clear?
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question