The destination address and destination port are the service side of the tuple.
The destination names the service side
The destination address is 203.0.113.5. The destination port is 443.
dst port=443
The service port matters
The first rule checks a different destination port, so this pinned port will matter when rows are tested.
tuple port=443
No name lookup is involved
The firewall sees bytes and integers here, not a web name or a DNS answer.
destination address=203.0.113.5
Summary
The tuple is now ready for ordered policy rows: source, destination, protocol, and destination port.
protocol=6