DNS as in quickest shortcut to insecurity with all kinds of powerful
counterparties watching over it.
For legitimate traffic, I suggest using your own caching resolver validating
DNS's RR with DNSSEC. To my knowledge "UNBOUND" is the best for this atm.
DNSSEC is not implemented by mostbigcashcompanies.com and will plug you
directly into the root servers/gTLDS owned by good/bad guys depending on what
activity you are running. DNSSEC will validate up to the domain user
domain.More info here http://nohats.ca/wordpress/blog/tag/dnssec/.
For private traffic you can decide to trust a third party. But there is
always a risk of them coming back at you. This is your decision after all.
For a normal user I strongly recommend a VPN service. I found
https://www.privateinternetaccess.com to be quite cheap.