Earlier quoted context omitted.
How does securing DNS lookups solve the MITM problem if the underlying traffic remains unencrypted? If you encrypt the traffic, you don't need secure DNS anymore.
That depends on what your trust model is. Somebody is resolving the DNS query, and then the result gets transmitted to you. If all you're worried about the result being MITM'd during transit, then encryption is sufficient. You can set up DNSCrypt to deal with this today [1]. But often the provider resolving the query is itself untrustworthy. Most providers these days (including OpenDNS) redirect invalid queries to th…
OpenDNS stopped doing this on June 6 2014: