They will probably forward all DNS traffic to their own resolvers by just changing the destination IP of any UDP traffic to port 53.
This won't work with DNSSEC or encrypted DNS though.
This won't work with DNSSEC or encrypted DNS though.
Encrypted DNS, though, like DoH or DNS-over-TLS or DNSCrypt, stops this cold.