I got around this limitation by setting up our own DNS over TLS server
which then forwards the DNS queries to the unsecure DNS server of our
choice. Certificate setup was fast, easy and free using Certbot. This
guide was very helpful:
https://www.ngi...