You could block outbound DNS at the router/firewall, or conceivably transparently proxy it there. If these don't sound easy to you (and I'm guessing they don't, I don't know if anyone has even written ...