Any way to block all DNS queries and whitelist some?

I’ll add a shameless plug for something I have been playing experimenting with:

Instead of blocking DoH, you can use it to block MS.

Think of it as changing the topic title to MSblock - Blocking MS via RPZ.

Do you know the domain names (maybe with sub-domains) you want to block?