[create a label to existing Namespace]
$ kubectl label namespace kube-system networking/namespace=kube-system
namespace/kube-system labeled

[create the NetworkPolicy]

---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-dns-access
spec:
  podSelector:
    matchLabels: {}
  policyTypes:
    - Egress
  egress:
    - to:
      - namespaceSelector:
          matchLabels:
                networking/namespace: kube-system
      ports:
        - port: 53
          protocol: UDP
        - port: 53
          protocol: TCP
