Today's BGP hijack of Cloudflare's 1.1.1.1 DNS service to an AS in China demonstrates how using a centralized DNS service is dangerous.
Running a recursive resolver, preferably with DNSSEC validation and enforcement, should help mitigate issues like what happened this morning.