I have been running OpenVPN on UDP/53 for a few years now. I figure that any network operator sophisticated enough to do deep packet inspection to detect real DNS traffic is also sophisticated enough to block outbound UDP/53 traffic.
I don't know why they serve full dns to unpaid users. Maybe to avoid os dns cache issues.
I've used iodine a few times in the past while traveling. Works like a charm.