

I had the same problem in my network and the solution is not easy.
Many, but many android apps are using Google dns servers just to leak the location of the phone (using the nearest geographical Google server).
The only way I found it was to instsll an opnsense router and redirect requests to port 53 to the internal dns server.
DoT (dns over tls) is blocked because it can not be redirected
DoH (dns over https) is (almost) imposible to block and still is a hole in current systems.
Good luck solving this




Yep, I checked that possibility too but it is like putting barriers into the see because :
Honestly is just the prey-predator competition. It won’t stop ever