Alert fails when 2 of 3 criteria are met

I am using the default "Alert me whe a rogue MAC address appears on the network" alert.

My understanding is that it should go off when the MAC address of a device is not in our white list.  I have a device that  passes the DNS and IP address rules just fine and is not in any of our Whie Lists.  The device gets put in the Rogue Devices list, but the alert does not trigger.  When I go to the Manage White list and do the "Test a device against all inclusion rules" with the MAC address it says the MAC address passes because it has passed the DNS rule.  I'm completely confused on this.  Any idea where I should start?

Thank you