This is the one router setting I change immediately on every network ...
You could block outbound DNS at the router/firewall, or conceivably transparently proxy it there. If these don't sound easy to you (and I'm guessing they don't, I don't know if anyone has even written ...
I've always ended up needing to install something like openwrt on my routers. I'm not particularly interested in continuing to need to do that as this seems like an obvious feature people might need ...