I’ve never seen anyone try and setup alerts for random DNS queries. If you’re in the position to know what domains are good, then why not simply use a whitelist?
Besides, even if you saw these queries you’d have no easy way of know I’d they were malicious or not.