Theoretically they could block outgoing UDP port 53 and outgoing TCP port 853 to anything but their DNS servers which would effectively block DNS and DNS over TLS respectively
Given the practice of ISPs using their so-called DNS servers to hijack NXDOMAIN results to sell ads and the fact that they as far as I know never did what I described implies that it's not worth it
|