Also assuming it is supported, what are the performance impacts of large (say 500k+) RPZ policies?
I forgot this part. In 6.x the main price will be CPU consumed when parsing the file. (which is asynchronous if you do a reload) And RAM to hold the resulting database. We've been quite careful about performance impact on processing DNS requests.