I imagine that if you wanted to block all DNS queries not going to government DNS, you put a block on packets routing to port 53. This is going to hit a lot of businesses that use their own DNS systems though. It would be harder to do a wide-ranging-but-not-total block, methinks, but I am not a net admin; I don't know the feasibility of mass port blocking.