Who says they have to be fake?
While a high number of requests for uncommon domains might trigger a lot of suspicion, you can cart out smaller amounts of data over DNS in ways that are really hard to detect. I've seen situations where data was being sent over DNS requests where the attacker merely held the ability to view the outgoing DNS traffic, but didn't really control (or want to risk modification) of traffic.