I agree with the idea that one should not trust DNS with any information one does not want public. I'm not totally convinced DNS is irreparably broken though. What are your thoughts on DNS over HTTPS?
DNS over HTTPS secures the connection between the client and their resolver. It doesn't improve anything else. It's still vulnerable to tampering at the still insecure connection between the resolver and the authoritative DNS server.