At present it seems bi-directional between all /ip/dns mDNS interfaces. So you can essentially create one mDNS zone for all specified interfaces. See http://forum.mikrotik.com/t/ros-7-16-rc4-mdns/177078/1
So if you want to get fine grained in what’s allowed or not allowed, that’s not possible today. With bridge filters, you can get down to the MAC address of what’s allowed or not.