Indeed, this is my preferred solution too. Unfortunately this doesn’t protect one from snooping by network intermediaries, although that’s much less of an issue in the EU due to privacy regulations. At least in principle, but it’s hard to be sure.
Run your own resolver on a vpc (perhaps in a different country, pay with bitcoin, adjust on your level of concern) and WireGuard to it (perhaps WireGuard over a service like mullvad)