aha, so checking this https://dnsleaktest.com and https://www.perfect-privacy.com/dns-leaktest/ using working config with dnsmasq, which is asking 1.1.1.1 in case it doesn't know I see opendns or google resolvers in results. could be a reason?
Yes, that's even better evidence that DNS is being hijacked. (I
don't imply malicious intent.)
--Vladimir