I'm disappointed by this situation where we have to shove encryption in at the application layer one application at a time because we couldn't get our act together with ipsec. I understand how it's come to be, but from an engineering perspective, it's absurd to move dns into https. Oh well, this is the nature of evolution, like the recurrent laryngeal nerve in a giraff.
Today, I have this setup for work. I don't like them spying on me while at work. So I have setup a local resolver that forwards some request to the companies resolver, and others over a secure line to a set of public resolver. I did not need to change any software.