Just use iptables on your firewall/router to reroute all traffic on port 53 to your DNS server.
The next game will probably be mitming these devices by flashing a new CA store.
There is no general solution to running an openly adversarial app/device in your network.
Keep in mind you're on HN-- we tend to be a more technical population :). If you're interested I found this on StackOverflow via Google: https://unix.stackexchange.com/questions/144482/iptables-to-...
You'll have to Google how to set up iptables/telnet or ssh on your router yourself, assuming it supports it.