I am not talking about DoT and DoH but plain vanilla unencrypted DNS requests but just using another port.
Is a list of known internet dns servers the only solution/workaround? (which it is for HTTPS) of can the firewall somehow detect that a DNS query is made?