The only way this could work would be to force OS vendors to have "trusted" DNS servers and ban the use of any custom setting.
Then again that would be a nightmare for large corporates that have customised internal DNSs, so I don't see it coming anytime soon.