DNS over TLS is a thing btw. You can shield your DNS from 3rd party listeners by providing all your DNS to some (single) company exclusively with pfSense. Choose your poison. https://www.netgate.com/blog/dns-over-tls-with-pfsense.html #servicetoot