Better instructions here, obvs: https://dnscrypt.org/
Install the dnscrypt-client and connect to one of the public nodes. I chose [https://nxt.ist]. You can "trust" these because they issue keypairs or something(?) but, caveat emptor.
But roll with the thick client because it's convenient and you'll get to see what you're in for... which is pretty boring if you're not running dig
or nslookup
all the time to see where your DNS entries are coming from. But then again, it's pretty boring. But at least they're encrypted?