Earlier quoted context omitted.
You're not wrong, but it is whack-a-mole, and this is one of our hammers.
Part of the problem is that it's a rather terrible, leaky, and easily-worked-around hammer. It mostly only continues to work because they haven't bothered to do simple things to prevent their more technical users from blocking it.
Roku devices hardcode 8.8.8.8 DNS in their software. So a Pi-Hole would be useless in a typical config. Evident by the constant hammering of dns.google in my firewall logs (dropped).
DNS filtering can only be effective if you intercept/drop all other outbound DNS traffic at the edge of your network.