This is more crazy. Is this achieved by hardcoding the DNS server IP address in the device?
At the router level, I then forced all 8.8.8.8 traffic to be transformed into traffic to my pihole.
You can do the next step, but you need a router that supports it and the patience to handle it.
You shouldn’t need to do this.
So, if it is using HTTPS for DNS resolution, I don’t know how you would block that.
If you could install a self-signed cert onto the device, you could MitM the HTTPS traffic and see what it is doing.
By filtering traffic sent from that particular device based on a query to your DNS filter to approve or deny the destination address. (Some implementation work probably required.)