The pi-hole I was running on Raspberry Pi got hacked. I only noticed the traffic when something unusual showed up on my node app console
But I agree that there's something other that's not ok. Compromised client (probably a computer) or a compromised router is my guesses.
It's stealth and has mitigations for DOS attacks.
I already run PiHole, but I might run this on a different box just to keep things simple.
Also, last I checked - port 51820 is reasonably well known, is it safe to use this default when forwarding traffic?
DNS is nowadays very robust and secure, and if you have unattended-upgrades configured there's literally zero reason to be frightened by DNS.