Granted, in this case if you block Google's DNS servers from routing, Chrome will use your system's name resolution configuration.
I barely use Chrome anymore (just for testing really) but the thought that any domain I wish to go to can be overridden by the browser by default - that's scary.
I mean what if Google doesn't like your website's content. They can block it on their DNS server and 99.999% of Chrome users would think something was wrong with your site.
Thank you, I hate it.
https://bugs.chromium.org/p/chromium/issues/detail?id=432236
(I'm obviously a bit biased on the matter because it affected me and cost me a silly amount of time to track down.)
They also claimed Firefox was doing the same thing, which is false and not really sufficient justification for not supporting things that MUST be supported.
[0] https://bugs.chromium.org/p/chromium/issues/detail?id=700354
Actually it was just annoying, not funny.
This has been discussed to death. Slippery slope, etc., etc.
pass in quick on { $lan $wireguard } proto udp to { 8.8.8.8 8.8.4.4 } port 53 rdr-to 192.168.2.1
Locally I run Unbound for caching, local dns zones and ad/malware domain blocking[2]. I have a DNS forwarder in Unbound configured to a local Stubby[1] instance that does dns over tls to Cloudflare.
Having done "big data" contract work for the largest telco in my current country of residence who are some of the worst skilled people I have ever work with, your local ISP is highly likely abusing your DNS history profiling your household for various questionable things just as much as Google. At least with Cloudflare they have a clear privacy policy[3] and I have faith their technical skill to anonymize data and use it can't be as bad as my ISP.
[1] https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Daemon+-+... [2] https://github.com/StevenBlack/hosts [3] https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...