It's extremely easy to induce a computer to make a DNS request. For example, embed an IMG tag in a web page pointing to the attacker's domain. Anyone loading that page will get the malicious DNS response.
DNS is UDP so you might just get a broken packet sent to you, I guess?
TCP or UDP transports.
Only if daemon is listening to the outside, which I hope is not the case by default.