I have run my own DNS resolver since that time when VeriSign decided to hijack all unregistered .com and .net domains (
https://en.wikipedia.org/wiki/Site_Finder); by running your own recursive DNS resolver, it could detect the hijacked responses and turn them back into the correct NXDOMAIN response.