Some IDS systems do it for you
I was using Darktrace at my last job and it would tell us when servers started querying domains they don't usually query so there are products that do it
Those systems usually flag based on a known set of “bad” domains, which wouldn’t stop this attack (they could just register a few new domains before starting the attack).