Understandably I got the following question from an operator (off-list):
How do we fix this?
This was my answer:
For fast exits we generally recommend to run a local caching and validating resolver like unbound, without using forwarding.
Besides being more reliable this also improves latency since many hostnames will be resolved using cached entries.
Regardless of how you proceed: Please do _not_ use Google's DNS server, they see already a lot of DNS traffic.
https://nymity.ch/dns-traffic-correlation/