A place to assess this, and decide what we do.
Reference Jeff Johnson tweet thread: https://twitter.com/lapcatsoftware/status/1326990296412991489
Counterpoint: Does Apple really log every app you run? A technical look
for reference: https://support.apple.com/en-us/HT210060
It says that the domain is used for Certificate Validation 馃

Also this: https://www.reddit.com/r/pihole/comments/e4kdhp/what_is_ocspapplecom/
Hi! This domain I have tracked, it is used to check certificates on Apple devices. It is not used for ad tracking or serving.
In some countries (including Vietnam), users install 3rd party apps, modded apps (like Youtube Cercuber, Youtube ++ to block ads..) or modded games. The developer signs the application to be able to install IPA files on iOS iPadOS devices, when Apple discovers that it will revoke the certificate through this domain. As a result, the installed application will not be able to open.
On iOS and iPadOS devices, blocking this domain name will prevent the system from checking for a valid certificate. And the installed application still opens, even though the certificate is revoked on the Apple server.
Here are some of the links I have captured

Most helpful comment
Hi! This domain I have tracked, it is used to check certificates on Apple devices. It is not used for ad tracking or serving.
In some countries (including Vietnam), users install 3rd party apps, modded apps (like Youtube Cercuber, Youtube ++ to block ads..) or modded games. The developer signs the application to be able to install IPA files on iOS iPadOS devices, when Apple discovers that it will revoke the certificate through this domain. As a result, the installed application will not be able to open.
On iOS and iPadOS devices, blocking this domain name will prevent the system from checking for a valid certificate. And the installed application still opens, even though the certificate is revoked on the Apple server.
Here are some of the links I have captured