For production environments it's really unnecessary to allow most egress traffic, but it's especially unnecessary to allow DNS. What addresses are your servers resolving publicly? You might want DNS for service discovery but obviously that requires no public resolvers, and any DNS exfil requires public resolvers. If you do require some public DNS I'd suggest limiting it considerably in a production environment, you rarely need legitimately arbitrary public DNS access. Even for niche scenarios (like maybe a "scan this URL" service) you can isolate the DNS resolution.
For corporate environments I feel like you can just drop all TXT records. The most trivial form of DNS exfil is always via TXT. Based on the code this appears to be TXT-based as well (hence the 255 character limit, which is because TXT records encode length with a single byte).
Is there even a legitimate use for a public TXT record for corporate devices? Genuine question, I legit do not know of one but I could easily be missing something.