Here's a good discussion and a guide to setting it up. I prefer using unbound to an encrypted DNS connection.