85% of the people of never change this one setting that can get their router hacked.
You could block outbound DNS at the router/firewall, or conceivably transparently proxy it there. If these don't sound easy to you (and I'm guessing they don't, I don't know if anyone has even written ...
Lesser-known fixes for well-known problems ...