Found out today that the 1.1.1.1 DNS service from CloudFlare actually has a TLS option. Didn't know you could do that.
Turns out you can.
Should be good for bypassing NXDOMAIN intercepts from my ISP :P