You might see something like this in a policy trace:
DNS lookup was unrestricted
The URL was rewritten to be normalized so there are not multiple cache objects for the same URL. Essentially, the original URL has special characters like "+" and ":". The ProxySG normalizes the URL by using the hex escape for the characters "%20" and "%3A" respectively, thus ensuring different forms of the URL access the same cached object entry.
This is perfectly valid according to the HTTP 1.1 RFC2616 (https://tools.ietf.org/html/rfc2616#section-3.2.3) and according to RFC 2396 (https://tools.ietf.org/html/rfc2396) on Uniform Resource Identifiers syntax.