I have dnsmasq enabled and am pointing to google primary and secondary dns servers . It all seems to be working fine .
If I go into Luci - Status -> RealTimeGraphs -> connections I see typically many entries(dozens or more) like this
UDP doesn’t have an “I’m done” exchange like TCP does, so “open” is done with a timer. No surprising to see several that are a few or tens of seconds open.
Are your clients using DNS on the router (or elsewhere in your network), or going direct to the outside? That might explain a very high number.